September was a month of management-plane failures. Most of what follows is not a flaw in how a device forwards traffic, but in the console or orchestrator that authenticates administrators and holds credentials for everything behind it. For Indian teams running multi-branch estates, one unpatched controller exposes every device beneath it.
India exposureBIG-IP APM fronts remote access for much of Indian banking, insurance and telecom. The risk applies where a virtual server carries an access policy with an OAuth profile or acts as an OAuth authorisation server, and F5 confirmed exploitation in the wild at disclosure.
ActionApply the hotfix for your train, or ask F5 Support for the interim iRule mitigation, then check OAuth authentication failures and TMM core files.
SourceF5 advisory, carried in CERT-EU advisory 2026-013, 22 September 2026; CISA Known Exploited Vulnerabilities catalogue, 22 September 2026.
2CriticalCVSS 10.0
Arista VeloCloud Orchestrator rated CVSS 10.0 and exploited before the fix — CVE-2026-93952
India exposureOn-premises VeloCloud Orchestrator runs SD-WAN for Indian enterprises and for providers managing customer branches. An attacker needs only network access to its web interface and the public part of an Edge certificate, and a compromised Orchestrator reaches every branch it configures.
ActionTrains 5.2, 6.1, 6.4 and 7.0 are affected, with fixes out for 5.2 and 6.4 first. Where none exists yet, take the web interface off untrusted networks.
SourceArista Security Advisory 0183, 22 September 2026; CISA KEV catalogue, 22 September 2026.
3
Check Point gateways and management servers under two separate attacks — CVE-2026-85102 and CVE-2026-93616
India exposureCVE-2026-85102 is pre-authentication code execution in VPN certificate validation, hitting Security Gateway and the Spark line that Indian mid-market firms and their service providers run. Check Point fixed it on 9 September and saw attempts against Spark customers from 12 September, none confirmed successful. CVE-2026-93616, a management-service path traversal, drew targeted attacks on 23 July.
ActionTreat these as two jobs. LivePatch covers the VPN flaw but not the management one, which Check Point says Take 28 and 29 leave open. Exact builds are in support notes sk1000117 and sk1000171.
SourceCheck Point security advisory, 22 September 2026; CISA KEV catalogue, 22 September 2026.
4CriticalCVSS 10.0
Cisco Secure Firewall Management Center worked by a state actor and a ransomware crew — CVE-2026-20079 and CVE-2026-20316
India exposureCVE-2026-20079 scores CVSS 10.0 and lets an unauthenticated attacker bypass the management web interface and run commands as root; CVE-2026-20316, a hard-coded credential flaw, chains with it. Talos is tracking three clusters: a financially motivated group using web shells, one linked to the Russian state actor Sandworm, and one tied to Qilin ransomware. Management Center sits above the firewall estate in Indian BFSI, manufacturing and government networks.
ActionApply the hardening release of 16 September and fixed builds, and take the interface off the internet. Rotate the credentials it holds, since patching does not undo earlier theft.
SourceBleepingComputer, 9 September 2026; Cisco Talos research reported by SecurityWeek, 10 September 2026; CISA KEV catalogue, 9 September 2026.
India exposureRated CVSS 10.0, it gives unauthenticated code execution through PHP smuggled in HTTP headers that runs when the platform renders automated email, and needs the /graphql endpoint reachable. Indian retail, direct-to-consumer brands and B2B distributors run Adobe Commerce and Magento Open Source widely, and staging instances are the weak point: internet-reachable, rarely patched on the storefront schedule.
ActionApply APSB26-146 alongside APSB26-138, enumerate every deployment including staging and QA, and confirm the version actually running rather than the change record.
SourceAdobe APSB26-146, 7 September 2026; Akamai Security Intelligence Group, 14 September 2026; CERT-In CIVN-2026-0458, 16 September 2026.
6
Fortinet CAPWAP flaw reaches the exploited catalogue eight months after its patch — CVE-2025-25249
India exposureA heap overflow in the CAPWAP daemon on UDP 5246 in FortiOS and FortiSwitchManager allows unauthenticated code execution. Fortinet patched it in January with no exploitation known then; CISA added it on 9 September. SOCRadar reports a campaign delivering PivotC2 since July, attributed to a financially motivated Russian-speaking group, with 178 compromised FortiGate devices from a target list above 30,000 still-unpatched addresses. FortiGate is among the most widely deployed firewalls in Indian networks.
ActionUpgrade, or remove fabric access from external interfaces and drop inbound UDP 5246 to 5249 with a local-in policy. Where PivotC2 artefacts appear, treat the configuration as exfiltrated.
SourceFortinet advisory FG-IR-25-084, 13 January 2026; SOCRadar research on the PivotC2 campaign; CISA KEV catalogue, 9 September 2026. In every item above the vulnerable component is the part of the estate administrators trust most and monitor least, and in four of them exploitation was already running when the fix went public. Patching closes the route in but settles nothing about what was taken while it stood open. For orchestrators and management consoles, credential rotation decides whether the intrusion ended. — Nirad Threat Research