# Posts by Amit Sheps

## Amit Sheps

Head of Product Marketing

Amit Sheps is a product marketing leader focused on making the cyber world safer. He’s spent years working across external and internal attack surface management and helping organizations protect OT, IoT, and cloud environments from real-world threats.

## [Emerging Threat: Cisco Catalyst SD-WAN Authentication Bypass (CVE-2026-20127)](https://www.cycognito.com/blog/emerging-threat-cisco-catalyst-sd-wan-authentication-bypass-cve-2026-20127/)

By [Amit Sheps](https://www.cycognito.com/blog/author/amit-sheps/) **・** February 26, 2026

CVE-2026-20127 is a critical authentication bypass in Cisco Catalyst SD-WAN Controller and Manager that allows unauthenticated remote access to centralized orchestration systems. Externally exposed SD-WAN infrastructure significantly increases enterprise risk, enabling policy manipulation, rogue peer insertion, and potential network-wide compromise.

## [Emerging Threat – Dell RecoverPoint for VMs Hardcoded Credential (CVE-2026-22769)](https://www.cycognito.com/blog/emerging-threat-dell-recoverpoint-for-vms-hardcoded-credential-cve-2026-22769/)

By [Amit Sheps](https://www.cycognito.com/blog/author/amit-sheps/) **・** February 24, 2026

CVE-2026-22769 is a hardcoded credential vulnerability in Dell RecoverPoint for VMs that can expose disaster recovery management interfaces to unauthorized access. Organizations with internet-reachable instances face elevated risk of administrative compromise and downstream infrastructure impact.

## [Permission to Ignore: Leveraging the CTEM Framework to Focus on Real Risk](https://www.cycognito.com/blog/permission-to-ignore-leveraging-the-ctem-framework-to-focus-on-real-risk/)

By [Amit Sheps](https://www.cycognito.com/blog/author/amit-sheps/) **・** February 19, 2026

Modern security frameworks often fail by surfacing endless vulnerabilities without context. This blog explores how the CTEM framework’s Validation stage provides “permission to ignore” theoretical risks, allowing teams to focus engineering resources exclusively on confirmed, evidence-based, and exploitable threats.

## [Emerging Threat: CVE-2026-1731 – BeyondTrust Privileged Access Exposure Risk](https://www.cycognito.com/blog/what-is-cve-2026-1731/)

By [Amit Sheps](https://www.cycognito.com/blog/author/amit-sheps/) **・** February 15, 2026

CVE-2026-1731 affects BeyondTrust privileged access deployments, introducing potential risk to internet-facing administrative interfaces. External exposure data shows cross-industry impact, particularly in technology, hospitality, healthcare, and energy sectors, where exposed access management systems may expand attackers’ paths to high-value enterprise infrastructure.

## [From Activity to Impact: How CTEM Refocuses Security KPIs](https://www.cycognito.com/blog/moving-from-activity-to-impact-how-ctem-refocuses-security-kpis/)

By [Amit Sheps](https://www.cycognito.com/blog/author/amit-sheps/) **・** February 12, 2026

Continuous Threat Exposure Management (CTEM) shifts security metrics from measuring activity to prioritizing impact. This refocuses reporting on urgent, validated issues and continuous testing coverage. By tracking remediation hours and material exposure reduction, organizations can effectively manage risk without creating unnecessary noise or alert fatigue.

## [Taking the Guesswork Out of CTEM](https://www.cycognito.com/blog/removing-the-guesswork-from-ctem/)

By [Amit Sheps](https://www.cycognito.com/blog/author/amit-sheps/) **・** February 5, 2026

CTEM reframed security around what attackers can actually reach and exploit. But Gartner didn’t provide an execution playbook. This blog breaks down what each stage demands in practice – and the anti-patterns that derail most programs.

## [SolarWinds Web Help Desk Vulnerabilities Update](https://www.cycognito.com/blog/solarwinds-web-help-desk-vulnerabilities-update/)

By [Amit Sheps](https://www.cycognito.com/blog/author/amit-sheps/) **・** February 4, 2026

SolarWinds disclosed multiple critical vulnerabilities in its Web Help Desk platform that may allow unauthenticated attackers to bypass security controls or execute code remotely. Organizations running exposed instances should patch immediately and assess external exposure to reduce risk.

## [Emerging Threat: CVE-2026-24858 – FortiCloud SSO Authentication Bypass](https://www.cycognito.com/blog/emerging-threat-cve-2026-24858-forticloud-sso-authentication-bypass/)

By [Amit Sheps](https://www.cycognito.com/blog/author/amit-sheps/) **・** February 2, 2026

CVE-2026-24858 is an authentication bypass vulnerability in FortiCloud SSO that can expose internet-facing management interfaces to unauthorized access. This Emerging Threat highlights the risk posed by externally exposed control planes and the importance of continuous external asset visibility.

## [Emerging Threat: CVE-2025-15467 – OpenSSL CMS AuthEnvelopedData Stack-Based Buffer Overflow](https://www.cycognito.com/blog/emerging-threat-cve-2025-15467-openssl-cms-authenvelopeddata-stack-based-buffer-overflow/)

By [Amit Sheps](https://www.cycognito.com/blog/author/amit-sheps/) **・** January 31, 2026

CVE-2025-15467 is a stack-based buffer overflow in OpenSSL CMS AuthEnvelopedData parsing. A crafted CMS message can corrupt memory before authentication, risking crashes or code execution in exposed services that process untrusted encrypted or signed content from external attackers over networks.

## [Emerging Threat: CVE-2026-24061 – Telnet Authentication Bypass in GNU Inetutils](https://www.cycognito.com/blog/emerging-threat-cve-2026-24061-telnet-authentication-bypass-in-gnu-inetutils/)

By [Amit Sheps](https://www.cycognito.com/blog/author/amit-sheps/) **・** January 28, 2026

CVE-2026-24061 is a newly assigned vulnerability that may allow remote code execution in externally exposed services due to improper input validation. Limited public details and lack of patches increase uncertainty, making comprehensive external asset visibility critical for effective risk assessment.
