Sep 2026: Monthly Security Bytes

Welcome to our LGA Monthly Security Bytes!

Here, you’ll find bite-sized security developments and practical insights to help you stay ahead of day-to-day security operations.

New Vulnerabilities Put Critical Enterprise Infrastructure in Focus

Enterprise infrastructure is facing renewed security scrutiny following newly disclosed vulnerabilities affecting VMware and Cisco Catalyst SD-WAN.

The vulnerabilities could enable attackers to gain unauthorised access, execute malicious code, escalate privileges, or compromise systems that organisations depend on for day-to-day operations.

For organisations using these technologies, successful exploitation could impact critical workloads, network connectivity, and operational continuity.

LGA helps organisations maintain greater visibility across their infrastructure, identify suspicious activity early, and respond to potential threats before they escalate into wider operational impact.

Key Security Updates
1. VMware Critical Vulnerabilities Impact Virtual Infrastructure

Security researchers have identified multiple critical vulnerabilities in VMware products that could allow attackers to bypass authentication, execute arbitrary code, steal sensitive data, and take full control of virtual environments.

These vulnerabilities affect widely used VMware platforms, including vCenter Server, ESXi, Workstation, and Fusion, putting both cloud-based and on-premises virtual infrastructure at risk. Since these platforms are core to enterprise IT operations, organizations that delay patching face a heightened risk of data breaches, service disruption, and full-scale system compromise.

Business IT infrastructure with security alert, cloud, servers and shield representing cybersecurity risks and system protection.

Critical Vulnerabilities were identified in the following:

CVE-2026-59309 & CVE-2026-59310

  • VMware Cloud Foundation (vCenter) versions 5.x, 9.0.x.x, 9.1.x.x
  • VMware vSphere Foundation (vCenter) versions 9.0.x.x, 9.1.x.x
  • VMware vCenter version 8.0
  • VMware Telco Cloud Platform (vCenter) versions 3.0, 4.x, 5.0.x, 5.1.x
  • VMware Telco Cloud Infrastructure (vCenter) version 3.0

 

CVE-2026-47876

  • VMware Cloud Foundation (vCenter) versions 5.x, 9.0.x.x, 9.1.x.x
  • VMware vSphere Foundation (vCenter) versions 9.0.x.x, 9.1.x.x
  • VMware ESX version 8.0
  • VMware Telco Cloud Platform versions (ESX) 5.0.x, 5.1.x

 

CVE-2026-41703

  • VMware Cloud Foundation (vCenter) versions 5.x, 9.0.x.x, 9.1.x.x
  • VMware vSphere Foundation (vCenter) versions 9.0.x.x, 9.1.x.x
  • VMware ESX version 8.0
  • VMware Telco Cloud Platform versions (ESX) 5.0.x, 5.1.x
  • VMware Workstation version 25H2
  • VMware Fusion version 25H2 


Recommended Action:
 Prioritize patching affected VMware environments to reduce the risk of virtual infrastructure compromise.

2. Cisco Catalyst SD-WAN Vulnerabilities Expose Enterprise Networks

Security researchers have identified critical vulnerabilities in Cisco Catalyst SD-WAN Software that could create direct pathways for unauthorized access, system compromise, and exposure of sensitive enterprise data.

These vulnerabilities affect a wide range of software releases, from versions earlier than 20.9 through the latest 26.1 release, leaving a broad range of Cisco SD-WAN deployments exposed. Since SD-WAN infrastructure connects and manages traffic across distributed enterprise networks, timely patching is essential to prevent connectivity disruption, data breaches, and unauthorized network access.

Critical Vulnerabilities were identified in the following:

  • Cisco Catalyst SD-WAN Software releases earlier than 20.9
  • Cisco Catalyst SD-WAN Software releases 20.9 through 20.16
  • Cisco Catalyst SD-WAN Software release 20.18
  • Cisco Catalyst SD-WAN Software release 26.1

 

Key vulnerabilities include CVE-2026-59309 (CVSS 9.8), CVE-2026-59310 (CVSS 9.8), CVE-2026-47876 (CVSS 9.3), and CVE-2026-41703 (CVSS 7.6).

Recommended Action: Update affected Cisco Catalyst SD-WAN systems to reduce the risk of unauthorised access, data exposure, and network compromise.

Secure Your Virtual and Network Environments Today

Can You Spot Suspicious Activity Before It Escalates?

With our 24/7 Security Monitoring, suspicious activity across critical infrastructure can be identified earlier, enabling faster detection and response before threats escalate.