⌁ DAY 41UNDERCOVERED IN US

CISA adds four exploited vulnerabilities to Known Exploited catalog

The US Cybersecurity and Infrastructure Security Agency added four new vulnerabilities to its Known Exploited Vulnerabilities catalog on 22 September 2026, including critical Check Point path traversal and certificate validation flaws showing active exploitation. By 24 September, CISA added two additional exploited vulnerabilities.

10 reportsother · primary

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-93616: Check Point Multiple Products — Check Point Multiple Products Path Traversal Vulnerability

json:cisa-kevprimary7d ago kagi ↗

Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on

CVE-2026-85102: Check Point Multiple Products — Check Point Multiple Products Improper Certificate Validation Vulnerability

json:cisa-kevprimary7d ago kagi ↗

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based

CISA Adds Four Known Exploited Vulnerabilities to Catalog

rss:cisa-advisoriesprimary7d ago kagi ↗

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability CVE-2026-9412

Check Point Quantum Security Management is affected by CVE-2026-93616 (CRITICAL, CVSS 9.8): unauthenticated attackers can upload & execute scripts via path traversal. Restrict access & monitor activit

mastodon:infosec-exchangeother7d ago kagi ↗

Check Point Quantum Security Management is affected by CVE-2026-93616 (CRITICAL, CVSS 9.8): unauthenticated attackers can upload & execute scripts via path traversal. Restrict access & monitor activity until patch info is released. https:// radar.offseq.com/threat/cve-20 26-93616-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-4344dfa6a4d98182 # OffSeq # CheckP

🤖 CVE-2026-93616: Check Point Security Management Server path traversal zero-day exploited in the wild. Unauthenticated attackers can upload and execute arbitrary scripts. Affects SMS, Log Server, Sm

mastodon:infosec-exchangeother7d ago kagi ↗

🤖 CVE-2026-93616: Check Point Security Management Server path traversal zero-day exploited in the wild. Unauthenticated attackers can upload and execute arbitrary scripts. Affects SMS, Log Server, SmartEvent. Emergency hotfix in R82.20. 🔗 https://www. bleepingcomputer.com/news/secu rity/check-point-patches-management-server-zero-day-exploited-in-attacks/ # CyberSec # CVE # Exploit # 0day

🚨 Check Point patches Management Server zero-day exploited in attacks ⠀ Check Point has released fixes for CVE-2026-93616, a vulnerability that allows unauthenticated attackers to upload and execute

mastodon:infosec-exchangeother7d ago kagi ↗

🚨 Check Point patches Management Server zero-day exploited in attacks ⠀ Check Point has released fixes for CVE-2026-93616, a vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts on affected management servers. ⠀ The company says a small number of customers have already been attacked. ⠀ Affected products include: • Security Management Server • Multi-Domain Se

Check Point patches actively exploited zero-day CVE-2026-93616 in Security Management Server. The critical CVSS 9.8 flaw enables unauthenticated remote code https:// deafnews.it/en/article/check-p oin

mastodon:infosec-exchangeother7d ago kagi ↗

Check Point patches actively exploited zero-day CVE-2026-93616 in Security Management Server. The critical CVSS 9.8 flaw enables unauthenticated remote code https:// deafnews.it/en/article/check-p oint-patches-zero-day-cve-2026-93616-in-management-server-cvss-98

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0922 ) CISA has added 4 new vulnerabilities to its Known Ex

mastodon:infosec-exchangeother6d ago kagi ↗

🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0922 ) CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder

CISA Adds Two Known Exploited Vulnerabilities to Catalog

rss:cisa-advisoriesprimary5d ago kagi ↗

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to t