TODAY
Cisco Firewall Auth Bypass Actively Exploited — Patch Your Perimeter Now
THE THREE
- KEV#1 · CVE-2026-20079
Cisco
What: If your organization uses Cisco Secure Firewall Management Center or Cisco Security Cloud Control, an attacker can bypass login entirely — no credentials needed — and potentially take over your firewall management plane, exposing your entire network. With an 88% exploit probability and active exploitation confirmed, this is as dangerous as it gets.
Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply Cisco's patch for FMC/SCC immediately; isolate management interfaces now.
- KEV#2 · CVE-2026-8037
Progress
What: Progress LoadMaster is a popular load balancer, and this flaw lets an unauthenticated attacker run any command on the appliance — meaning full device compromise and a foothold into your internal network. It has been actively exploited for over six weeks.
Why it moved: Actively exploited · Widely deployed · Critical severity · 77% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch Progress LoadMaster to the latest fixed version without delay.
- KEV#3 · CVE-2026-85046
Chrome
What: This Chrome vulnerability lets an attacker run malicious code in your browser just by getting a user to visit a crafted webpage — a classic drive-by attack that can lead to credential theft or malware installation on any workstation running an unpatched version. Chrome is nearly universal, so your exposure is very wide.
Why it moved: Actively exploited · Everyone runs this
Who is exploiting: Actively-exploited (CISA KEV)
Action · Force-update all Chrome browsers to version 152.0.7977.82 or later today.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 11M
- Relationships
- 67M
- Threat actors
- 237
- Indicators
- 652k
- Feeds live
- 19
- Sources total
- 21
Ingest paused — figures are the last-good snapshot, not live.
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.