Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: edge (4 articles)Clear

Cisco patches exploited Firewall Management Center flaw that grants built-in account access

Cisco has patched a flaw in Secure Firewall Management Center that attackers were already exploiting to log into devices. Tracked as CVE-2026-20316, it stems from static credentials for a low-privilege account built into the software, letting an unauthenticated remote attacker sign in and read sensitive data. Cisco scored it 5.3 but rated it High because the access can be chained with other flaws to escalate privileges. In the same cycle it patched CVE-2026-20079, a separate critical authentication bypass that reaches root, and shipped one set of hot fixes with a shared indicator suggesting the two could be combined. There are no workarounds.

Check
Upgrade Secure FMC to a fixed release now, and check for compromise by searching device logs for references to /var/tmp/license.tmp, which Cisco lists as an indicator.
Affected
Organizations running Cisco Secure Firewall Management Center releases 7.0, 7.2, 7.4, 7.6, 7.7, or 10.0 (CVE-2026-20316); the flaw is exploited, and chaining with the root-level bypass raises the stakes.
Fix
Apply Cisco's hot fixes, since there is no workaround, keep the FMC management interface off the public internet, and if the indicator appears, rotate all device credentials, keys, and certificates.

CISA orders agencies to patch two exploited Fortinet FortiSandbox flaws

CISA has added two critical Fortinet FortiSandbox vulnerabilities to its exploited-vulnerabilities catalog and ordered federal agencies to patch them by July 19. Tracked as CVE-2026-39808 and CVE-2026-25089, both are operating-system command injection flaws that let an unauthenticated attacker run commands remotely with low complexity and no user interaction. Fortinet disclosed and fixed them in April and June, and threat intelligence firm Defused reported in-the-wild abuse of FortiSandbox flaws in June. FortiSandbox is a threat-detection appliance, and Fortinet gear sits at many network edges, so these devices are a recurring target in espionage and ransomware campaigns, making prompt patching important.

Check
Identify Fortinet FortiSandbox appliances in your environment, check their versions against Fortinet's advisories for these flaws, and upgrade to the fixed releases, prioritizing any internet-reachable or edge-facing devices.
Affected
Organizations running affected Fortinet FortiSandbox versions (CVE-2026-39808, CVE-2026-25089); unauthenticated attackers can run commands remotely, and active exploitation of FortiSandbox flaws has been reported, making unpatched appliances a real risk.
Fix
Upgrade FortiSandbox to the fixed versions, such as 4.4.9 for the April flaw, restrict and monitor management access to these appliances, and review logs and configurations for unauthorized commands or changes.

Progress tells ShareFile customers to shut down file servers over credible threat

Progress Software has told ShareFile customers to immediately shut down the on-premises Windows servers running Storage Zone Controllers, citing a "credible external security threat" against its enterprise file-sharing platform. The company has temporarily disabled access to affected accounts and says it has no sign of unauthorized access yet, but it has not disclosed what the threat is or whether a vulnerability is involved. Ordering a full shutdown rather than a patch strongly suggests there is no fix available. Only self-hosted Storage Zone Controllers, which typically sit internet-facing at the network edge, are affected, not cloud-only ShareFile. Progress also makes MOVEit, whose 2023 zero-day was mass-exploited by the Clop group.

Check
Determine whether you run ShareFile Storage Zone Controllers, and if so, follow Progress's guidance to shut down the hosting Windows servers now, while preserving system and administrative logs for investigation.
Affected
Organizations running on-premises ShareFile Storage Zone Controllers, which broker files between local storage and the ShareFile cloud and are usually internet-facing; cloud-only ShareFile accounts are not affected by this advisory.
Fix
Shut down Storage Zone Controller servers as Progress directs until a fix or all-clear is issued, review recent administrative activity and internet exposure, and watch for Progress updates.

Microsoft reverses course on Edge: saved passwords will no longer load into memory at startup

Microsoft has flipped its position on Edge keeping saved passwords decrypted in memory the moment the browser launches. After originally telling the researcher who reported it that the behavior was 'by design' and not a security issue, Microsoft now says future Edge builds will stop loading the password store into memory at startup. The fix is already live in the Canary channel and will reach Stable, Beta, Dev, and Extended Stable in build 148. The original disclosure came with a working tool that lets an administrator on a shared Windows machine dump other users' Edge passwords by reading process memory.

Check
Inventory Edge installs across your fleet. Check the current Edge version via edge://settings/help and flag anything below build 148.
Affected
Microsoft Edge versions before build 148 (Stable, Beta, Dev, Canary, Extended Stable) that store credentials via Edge's built-in password manager.
Fix
Update Edge to build 148 or newer when it ships. Until then, disable Edge's built-in password manager on sensitive endpoints and limit local admin rights on shared machines.