conv.

All stories
SecurityActive today · day 7

Check Point patches exploited zero-day; Cisco, D-Link also warn of active attacks

Three vendors disclose maximum-severity, actively exploited vulnerabilities within a single week, capping a run of urgent security advisories.

What to know

  • Three separate vendors — Cisco, D-Link, and Check Point — disclosed maximum- or critical-severity zero-days under active exploitation within the same week.
  • D-Link's DIR-822A router flaw (CVE-2026-86296) has public proof-of-concept exploit code but no patch, leaving legacy devices exposed.
  • Check Point's advisory covers two vulnerabilities: a new Security Management Server zero-day (CVE-2026-85102) and a previously known Site-to-Site VPN bug (CVE-2026-93616) now confirmed exploited.
  • Cisco's Identity Services Engine bug carries the maximum CVSS score of 10.0, indicating unauthenticated remote exploitation with full impact.

Cisco VendorD-Link VendorCheck Point Software Vendor

How it unfolded 5 developments, newest first · click a bar or a number to jump articlesposts

Peak 4 pieces in two hours at Sep 17, 2 AM; 21 pieces over 7 days (6 articles · 15 posts) Sep 17, 2 AM — 4 pieces · 2 articles · 2 posts — Google News 2, Mastodon 2Sep 17, 4 AM — quietSep 17, 6 AM — quietSep 17, 8 AM — quietSep 17, 10 AM — quietSep 17, 12 PM — quietSep 17, 2 PM — quietSep 17, 4 PM — quietSep 17, 6 PM — quietSep 17, 8 PM — quietSep 17, 10 PM — quietSep 18, 12 AM — quietSep 18, 2 AM — quietSep 18, 4 AM — quietSep 18, 6 AM — quietSep 18, 8 AM — quietSep 18, 10 AM — quietSep 18, 12 PM — quietSep 18, 2 PM — quietSep 18, 4 PM — quietSep 18, 6 PM — quietSep 18, 8 PM — quietSep 18, 10 PM — quietSep 19, 12 AM — quietSep 19, 2 AM — quietSep 19, 4 AM — quietSep 19, 6 AM — quietSep 19, 8 AM — quietSep 19, 10 AM — quietSep 19, 12 PM — quietSep 19, 2 PM — quietSep 19, 4 PM — quietSep 19, 6 PM — quietSep 19, 8 PM — quietSep 19, 10 PM — quietSep 20, 12 AM — quietSep 20, 2 AM — quietSep 20, 4 AM — quietSep 20, 6 AM — quietSep 20, 8 AM — quietSep 20, 10 AM — quietSep 20, 12 PM — quietSep 20, 2 PM — quietSep 20, 4 PM — quietSep 20, 6 PM — quietSep 20, 8 PM — quietSep 20, 10 PM — quietSep 21, 12 AM — quietSep 21, 2 AM — quietSep 21, 4 AM — quietSep 21, 6 AM — quietSep 21, 8 AM — quietSep 21, 10 AM — quietSep 21, 12 PM — quietSep 21, 2 PM — quietSep 21, 4 PM — quietSep 21, 6 PM — quietSep 21, 8 PM — quietSep 21, 10 PM — quietSep 22, 12 AM — quietSep 22, 2 AM — quietSep 22, 4 AM — quietSep 22, 6 AM — 2 pieces · 2 posts — Mastodon 2Sep 22, 8 AM — quietSep 22, 10 AM — 2 pieces · 2 posts — Mastodon 2Sep 22, 12 PM — quietSep 22, 2 PM — 1 piece · 1 post — Mastodon 1Sep 22, 4 PM — quietSep 22, 6 PM — quietSep 22, 8 PM — quietSep 22, 10 PM — quietYesterday, 12 AM — 1 piece · 1 article — Newswires 1Yesterday, 2 AM — 4 pieces · 2 articles · 2 posts — Mastodon 3, Newswires 1Yesterday, 4 AM — 1 piece · 1 post — Mastodon 1Yesterday, 6 AM — 1 piece · 1 post — Hacker News 1Yesterday, 8 AM — 3 pieces · 3 posts — Mastodon 3Yesterday, 10 AM — quietYesterday, 12 PM — 1 piece · 1 article — Newswires 1Yesterday, 2 PM — quietYesterday, 4 PM — 1 piece · 1 post — Mastodon 1Yesterday, 6 PM — quietYesterday, 8 PM — quietYesterday, 10 PM — quietToday, 12 AM — quiet 12345
Sep 18Sep 19Sep 20Sep 21Sep 22yesterdaynow · 2:58 AM ET
  1. 5

    SecurityWeek confirms Check Point zero-day patch and impact

    Coverage confirmed the critical-severity Check Point Management Server flaw allowed unauthenticated attackers to upload and execute arbitrary scripts before the emergency hotfix was issued.

    1. first by SecurityWeek, 1d ago

    • ottoto2017@prattohome.com

      「F5社、BIG-IP APMのゼロデイ脆弱性(リモートコード実行攻撃で悪用される)を修正 」: # BLEEPINGCOMPUTER 「F5は、リモートコード実行攻撃で悪用されているBIG-IP APMの重大なゼロデイ脆弱性に対処するためのセキュリティアップデートをリリースしました。 BIG-IP APM(Access Policy Managerの略)は、同社の集中型アクセス管理プロキシソリューションであり、管理者が組織のネットワーク、アプリケーション、クラウド、およびアプリケーションプログラミングインターフェイス(API)へのアクセスを安全に保護するのに役立ちます。 CVE-2026-94127 として追跡されている この脆弱性は、 BIG-IP…

      ottoto2017@prattohome.comMastodon23h agoview on Mastodon ↗
    2 more of the top 3 · 4 posts in this stretch
    • BleepingComputer@infosec.exchange

      F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. https://www. bleepingcomputer.com/news/secu rity/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/

      BleepingComputer@infosec.exchangeMastodon23h agoview on Mastodon ↗
    • sambowne@infosec.exchange

      Check Point warns of Management Server zero-day exploited in attacks https://www. bleepingcomputer.com/news/secu rity/check-point-patches-management-server-zero-day-exploited-in-attacks/

      sambowne@infosec.exchangeMastodon16h agoview on Mastodon ↗
    all of them →
  2. 4

    Check Point discloses two exploited CVEs, including an older VPN bug

    Check Point's advisory identified the new zero-day as CVE-2026-85102 in Security Management Server and separately marked an older Site-to-Site VPN pre-authentication vulnerability, CVE-2026-93616, as also being exploited in the wild.

    • campuscodi@mastodon.social

      Check Point has disclosed a zero-day (in Security Management Server) and marked an older bug also as exploited in the wild (in Site-to-Site VPN) https:// blog.checkpoint.com/security/s ecurity-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/

      campuscodi@mastodon.socialMastodon1d agoview on Mastodon ↗
  3. 3

    Check Point issues emergency hotfixes for Management Server zero-day

    Check Point Software released emergency hotfixes for a critical Security Management Server vulnerability that could let unauthenticated attackers upload and execute arbitrary scripts.

    • BleepingComputer@infosec.exchange

      Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. https://www. bleepingcomputer.com/news/secu rity/check-point-patches-management-server-zero-day-exploited-in-attacks/

      BleepingComputer@infosec.exchangeMastodon1d agoview on Mastodon ↗
  4. 2

    D-Link warns of unpatched zero-day in legacy DIR-822A routers

    D-Link disclosed CVE-2026-86296, a maximum-severity vulnerability with public proof-of-concept exploit code and no available patch, affecting legacy DIR-822A dual-band Wi-Fi routers.

    • BleepingComputer@infosec.exchange

      D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. https://www. bleepingcomputer.com/news/secu rity/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers/

      BleepingComputer@infosec.exchangeMastodon1d agoview on Mastodon ↗
  5. 4 days quiet
  6. 1

    Cisco patches max-severity ISE auth-bypass zero-day

    Cisco released security updates for a maximum-severity (CVSS 10.0) authentication bypass vulnerability in Identity Services Engine that attackers were actively exploiting in the wild.

    1. 2 outlets first by The Hacker News, 6d ago · also BleepingComputer · read ↗

    • BleepingComputer@infosec.exchange

      Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. https://www. bleepingcomputer.com/news/secu rity/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/

      BleepingComputer@infosec.exchangeMastodon6d agoview on Mastodon ↗

Also covered reported alongside — the timeline has no entry for these yet

  1. first by Mastodon, 23h ago · also SecurityWeek, The Register

    2 more headlines

What people are saying 1 voices from 1 site · best of 8 · verbatim