Check Point patches exploited zero-day; Cisco, D-Link also warn of active attacks
Three vendors disclose maximum-severity, actively exploited vulnerabilities within a single week, capping a run of urgent security advisories.
What to know
- Three separate vendors — Cisco, D-Link, and Check Point — disclosed maximum- or critical-severity zero-days under active exploitation within the same week.
- D-Link's DIR-822A router flaw (CVE-2026-86296) has public proof-of-concept exploit code but no patch, leaving legacy devices exposed.
- Check Point's advisory covers two vulnerabilities: a new Security Management Server zero-day (CVE-2026-85102) and a previously known Site-to-Site VPN bug (CVE-2026-93616) now confirmed exploited.
- Cisco's Identity Services Engine bug carries the maximum CVSS score of 10.0, indicating unauthenticated remote exploitation with full impact.
Cisco VendorD-Link VendorCheck Point Software Vendor
How it unfolded 5 developments, newest first · click a bar or a number to jump articlesposts
-
5
SecurityWeek confirms Check Point zero-day patch and impact
Coverage confirmed the critical-severity Check Point Management Server flaw allowed unauthenticated attackers to upload and execute arbitrary scripts before the emergency hotfix was issued.
-
first by SecurityWeek, 23h ago
-
O
「F5社、BIG-IP APMのゼロデイ脆弱性(リモートコード実行攻撃で悪用される)を修正 」: # BLEEPINGCOMPUTER 「F5は、リモートコード実行攻撃で悪用されているBIG-IP APMの重大なゼロデイ脆弱性に対処するためのセキュリティアップデートをリリースしました。 BIG-IP APM(Access Policy Managerの略)は、同社の集中型アクセス管理プロキシソリューションであり、管理者が組織のネットワーク、アプリケーション、クラウド、およびアプリケーションプログラミングインターフェイス(API)へのアクセスを安全に保護するのに役立ちます。 CVE-2026-94127 として追跡されている この脆弱性は、 BIG-IP…
2 more of the top 3 · 4 posts in this stretch
-
B
F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. https://www. bleepingcomputer.com/news/secu rity/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/
-
S
Check Point warns of Management Server zero-day exploited in attacks https://www. bleepingcomputer.com/news/secu rity/check-point-patches-management-server-zero-day-exploited-in-attacks/
-
-
4
Check Point discloses two exploited CVEs, including an older VPN bug
Check Point's advisory identified the new zero-day as CVE-2026-85102 in Security Management Server and separately marked an older Site-to-Site VPN pre-authentication vulnerability, CVE-2026-93616, as also being exploited in the wild.
-
C
Check Point has disclosed a zero-day (in Security Management Server) and marked an older bug also as exploited in the wild (in Site-to-Site VPN) https:// blog.checkpoint.com/security/s ecurity-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
-
-
3
Check Point issues emergency hotfixes for Management Server zero-day
Check Point Software released emergency hotfixes for a critical Security Management Server vulnerability that could let unauthenticated attackers upload and execute arbitrary scripts.
-
B
Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. https://www. bleepingcomputer.com/news/secu rity/check-point-patches-management-server-zero-day-exploited-in-attacks/
-
-
2
D-Link warns of unpatched zero-day in legacy DIR-822A routers
D-Link disclosed CVE-2026-86296, a maximum-severity vulnerability with public proof-of-concept exploit code and no available patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
-
B
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. https://www. bleepingcomputer.com/news/secu rity/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers/
-
- 4 days quiet
-
1
Cisco patches max-severity ISE auth-bypass zero-day
Cisco released security updates for a maximum-severity (CVSS 10.0) authentication bypass vulnerability in Identity Services Engine that attackers were actively exploiting in the wild.
-
2 outlets first by The Hacker News, 6d ago · also BleepingComputer · read ↗
-
B
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. https://www. bleepingcomputer.com/news/secu rity/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/
-
Also covered reported alongside — the timeline has no entry for these yet
-
first by Mastodon, 22h ago · also SecurityWeek, The Register
2 more headlines
- Critical F5 BIG-IP Vulnerability Exploited as Zero-Day SecurityWeek · 22h ago
- Someone's attacking a critical 0-day RCE in F5 BIG-IP APM The Register · 11h ago
What people are saying 1 voices from 1 site · best of 8 · verbatim
- Yesterday
-
P
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers https:// thehackernews.com/2026/09/f5-p atches-critical-big-ip-apm-zero-day.html