Security.io Intelligence DeskThursday, 10 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Today’s lead:Cisco confirms active exploitation against the firewall management planeBlueMoon turns the browser patch gap into a shared espionage capabilityEU product-security reporting clocks start tomorrowSpringfield keeps schools closed as cyber disruption reaches…
Front page · Daily intelligence

Cisco confirms active exploitation against the firewall management plane

Cisco has now confirmed active exploitation of a maximum-severity authentication bypass that can provide unauthenticated attackers with root access to Secure Firewall Management Center.

Cisco’s September revision confirms that CVE-2026-20079 is being exploited. Crafted HTTP requests can bypass authentication and execute scripts or commands as root on affected Secure FMC systems. Cisco provides a specific log check and release-specific hot fixes, but no workaround.

Why today: Cisco’s March disclosure moved above the other selected developments because the September 9 confirmation of active exploitation changes both the decision and the closure standard for a privileged firewall control plane. The new fact is not the vulnerability…
“Inventory every on-premises Cisco Secure FMC instance, release branch and management-interface exposure.”

Decision owner: Network security leadership, with incident response, infrastructure operations and vulnerability management.

Decision horizon: Immediate: hunt and contain before accepting patch deployment as closure.

Continue the lead analysis →

Full source ledger, evidence of closure and escalation triggers appear in the article.

1Dominant story selected for executive consequence
4Supporting developments, tightly edited
7 minTarget time to understand today’s priorities
0Programmatic banners, pop-ups or paywalls

Today’s ledger

Selected for consequence, not headline volume
Lead decision

Cisco confirms active exploitation against the firewall management plane

Cisco’s September revision confirms that CVE-2026-20079 is being exploited. Crafted HTTP requests can bypass authentication and execute scripts or commands as root on affected Secure FMC…

Today’s action: Inventory every on-premises Cisco Secure FMC instance, release branch and management-interface exposure.

Threat Intelligence

BlueMoon turns the browser patch gap into a shared espionage capability

Proofpoint’s September 9 research documents rapid adoption of BlueMoon by four espionage-focused threat clusters. The kit combines CVE-2026-85046, an unnumbered V8 sandbox escape and CVE-2026-85880 on…

Today’s action: Inventory browser versions and Windows build combinations across targeted user groups.

Regulatory

EU product-security reporting clocks start tomorrow

Cyber Resilience Act Article 14 reporting applies from September 11, 2026. Manufacturers must provide a 24-hour early warning and a 72-hour notification for actively exploited vulnerabilities…

Today’s action: Name the accountable CRA reporting officer and deputies.

Third-Party Risk

Vendor-held API credentials expose Veradigm patient data

Veradigm’s SEC filing states that an unauthorised party obtained credentials from a third-party vendor environment and used them to download patient personal data through a limited…

Today’s action: Ask Veradigm whether your organisation or patients are affected.

Signal desk

Interactive editorial evidence
Lead decision score

Cisco Secure FMC enterprise decision score

Hover or tap a bar for its exact value and the editorial meaning behind it. Keyboard: focus the chart and use ↑ or ↓.

Scores are editorial, not source metrics: 0–100 based on verified exploitation, privileged control-plane placement and recovery consequence.

Higher scores indicate greater executive consequence, urgency and decision value. Security.io editorial scoring is a prioritisation aid, not a prediction of incident probability.Source: Security.io editorial score, 0–100, based on the cited Cisco evidence.
Evidence accumulated across the edition

Verified references behind today’s five decisions

Hover or tap a point to see the story title, new references, cumulative evidence, source mix and why the story entered today’s edition. Keyboard: use ← or →.

This line shows cumulative cited references across the lead and four supporting briefs.

primary: 11 · research: 1 · reporting: 4 · context: 0

Appointments, dinners & sponsored intelligence

Paid placements · clearly separated
Open calendar
Sponsor's Notice · Security.io

Private CISO Roundtable: The 2027 Security Agenda

A closed-door, vendor-neutral discussion for senior security leaders hosted by Security.io.

Request details →
Invitation only
Sponsor's Notice · Security.io

Security.io CISO Dinner: Decisions That Cannot Wait

An invitation-only dinner for CISOs and deputies focused on consequential security decisions.

Request an invitation →
Black Hat week
Paid Placement · Security.io

Security.io at Black Hat: Executive Intelligence Dinner

A private dinner and briefing for security leaders during Black Hat week.

Join the interest list →