Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Cisco tops a five-vendor KEV batch

2 min read
12:09UTC

CISA drew two more Cisco flaws into its catalogue this fortnight, alongside a SimpleHelp bypass that reopens the managed-service-provider route used by DragonForce in 2025.

TechnologyDeveloping
Key takeaway

Cisco tops the KEV catalogue with five entries since April across three separate product lines.

CISA cleared two Known Exploited Vulnerabilities (KEV) batches this fortnight. On Thursday 25 June, due 28 June, it listed a Cisco Unified Communications Manager server-side request forgery (SSRF) flaw, CVE-2026-20230, and a flaw in PTC Windchill, CVE-2026-12569, allowing unauthenticated remote code execution (RCE). On Monday 29 June, due 2 July, came a SimpleHelp single-sign-on (SSO) authentication bypass, CVE-2026-48558, a Cisco Catalyst SD-WAN Manager path traversal, CVE-2026-20262, and a Joomla Widget Factory flaw, CVE-2026-48907. 1

That makes Cisco the most repeat-listed vendor on this beat, with five KEV entries across three product lines since April, following the CVSS-10 Catalyst flaw that the UAT-8616 group was already exploiting in May . An SSRF flaw lets an attacker make a server issue requests on their behalf, reaching systems the attacker cannot touch directly. SimpleHelp is the remote monitoring and management (RMM) tool tied to the 2025 DragonForce campaign against managed service providers (MSPs), and an SSO bypass re-opens the same one-to-many route into every downstream client.

PTC Windchill sits in the product-lifecycle-management (PLM) systems that aerospace, automotive and defence suppliers use to hold engineering data. An unauthenticated RCE there is a supply-chain entry rather than a perimeter one: the attacker needs no credential, and the prize is the design data a supplier holds on behalf of its customers.

Deep Analysis

In plain English

Managed service providers, or MSPs, are companies that IT departments hire to remotely manage computers for lots of different clients at once, often using a tool called SimpleHelp. A newly listed flaw lets an attacker skip the login step in SimpleHelp, which matters because whoever controls that one tool can potentially reach every client the MSP looks after. Cisco and the website-building tool Joomla also had flaws added to the same must-fix list this fortnight. The common thread is that all five bugs let an attacker either break into a network from outside or move around inside it once they are in, and criminals often buy and sell working exploits for bugs like these rather than write their own.

Deep Analysis
Root Causes

SimpleHelp, like most remote monitoring and management tools built for MSPs, runs on a one-to-many trust model: a single administrator credential on the server can push software to every client endpoint it manages, which is exactly the feature ransomware crews weaponise once they compromise the server itself.

Cisco's Catalyst SD-WAN Manager path-traversal flaw follows the same access-broker pattern already logged against Cisco SD-WAN infrastructure through the UAT-8616 cluster: a criminal broker validates access into edge network-management consoles, then resells it to whichever ransomware affiliate pays first, rather than exploiting the flaw directly.

What could happen next?
  • Risk

    Any MSP running a self-hosted, internet-reachable SimpleHelp instance faces a Kaseya-scale downstream exposure if the SSO bypass is exploited before patching, since one compromised server reaches every managed client.

  • Consequence

    Cisco's repeated appearance in KEV batches this fortnight, alongside the SD-WAN Manager flaw already tied to the UAT-8616 broker network, suggests the same access-broker group may be scouting or reselling access to this new path-traversal bug.

First Reported In

Update #9 · FortiBleed harvest linked to Lynx crew

CISA· 4 Jul 2026
Read original
Causes and effects
This Event
Cisco tops a five-vendor KEV batch
A repeat run of Cisco flaws and a SimpleHelp bypass put both vendor concentration and the managed-service-provider supply chain back on defenders' radar.
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.