Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

Check Point patches two critical VPN certificate flaws enabling unauthenticated code execution

Check Point patched two critical flaws in how its firewall and management products handle VPN certificates, each scored 9.8, that could let an unauthenticated remote attacker run code. CVE-2026-85102 is improper certificate-trust validation during VPN negotiation that can lead to code execution on the Security Gateway. CVE-2026-85103 is a heap overflow while decoding a certificate's structure, affecting both the gateway and the management server. Notably, because the second flaw is about certificate processing, Check Point says it could be triggered even where VPN is not running, so management servers need the fix regardless. Check Point found the issues internally and reports no exploitation yet, though its products were attacked twice this year.

Check
Apply Check Point's Live Patch or the latest Jumbo Hotfix to affected gateways and management servers now, and patch management servers even with the VPN blade off, since certificate processing stays reachable.
Affected
Organizations running affected Check Point Quantum Security Gateway and Management systems (CVE-2026-85102, CVE-2026-85103); an unauthenticated attacker could execute code through VPN certificate handling, and management servers are affected without VPN in use.
Fix
Patch gateways and management servers promptly, confirm Live Patch installed, restrict who can reach these devices, monitor for anomalous certificate-related activity, and treat security infrastructure as a repeatedly targeted asset.

Identity firm IDScan breach exposes scans of 153 million driver's licenses

Identity-verification company IDScan confirmed that attackers accessed customer data in its cloud, behind a dark-web marketplace offering scans of more than 153 million US and Canadian driver's licenses, plus names and government-ID numbers. IDScan authenticates government IDs for businesses ranging from banks to car-rental agencies to cannabis and gun retailers, which makes it an aggregator of everyone's identity documents and a single point of mass failure. Investigative journalist Brian Krebs traced the marketplace back to IDScan by matching document scans to occasions when IDs were presented. The FBI is investigating and lawsuits have been filed. Because these are scanned government IDs, victims cannot simply rotate a leaked driver's license.

Check
People who presented IDs to businesses using IDScan should watch for identity and document fraud and use any offered monitoring, and organizations should reassess how much identity-document data their verification vendors retain.
Affected
Roughly 153 million people whose driver's license scans, names, and government-ID numbers were exposed through IDScan; scanned identity documents enable durable document fraud a victim cannot undo by changing a password.
Fix
For organizations, minimize retained identity-document images, encrypt and tightly access-control them, vet identity-verification vendors as high-value aggregators, and prefer verification methods that avoid storing reusable copies of government IDs.

BlueMoon exploit kit chains Chrome and Windows zero-days to reach SYSTEM

Researchers at Proofpoint and Volexity detailed BlueMoon, a modular exploit kit that chains three zero-day flaws to take a victim from a malicious web page to full control of their Windows machine. It uses two Chrome flaws, CVE-2026-85046 and CVE-2026-87491, to run code in the browser and escape its sandbox, then a Windows kernel bug, CVE-2026-85880, to gain SYSTEM privileges. Both Chrome flaws were "patch-gap" zero-days: their fixes were already public in Chromium's open source before reaching stable Chrome, so attackers reverse-engineered the fixes to hit users who had not yet updated. Multiple espionage groups adopted the shared kit within days, and researchers expect wider use.

Check
Update Chrome and Chromium-based browsers and apply Windows patches immediately, since all three chained flaws are fixed, and prioritize browser updates because attackers weaponize public Chromium fixes before they reach stable releases.
Affected
Users on outdated Chrome or Chromium browsers and unpatched Windows; the kit chains browser code execution, sandbox escape, and a kernel flaw to reach SYSTEM from a single web page.
Fix
Keep browsers and operating systems updated aggressively and automatically, treat a public browser-engine fix as a signal to update fast, deploy the vendors' indicators, and reduce exposure to drive-by web attacks.

Voice phishing turns personal devices into a path to Microsoft 365 data

Researchers describe attackers using voice phishing calls to talk employees into granting access from their personal devices, then reaching Microsoft 365 and corporate data through the trust the user extends. The attackers do not hack the device; they convince the person, then use Microsoft's Graph API to identify valuable targets and pass access to extortion groups like ShinyHunters. Because the weakness is the user's decision rather than the hardware, banning personal devices would not stop it. The stronger defense is tightening identity and authentication and limiting what a compromised account can actually do, so that tricking one person yields far less to the attacker.

Check
Train staff to be suspicious of unsolicited support and IT calls that ask them to approve access or run steps, and verify such requests through a known internal channel before acting.
Affected
Organizations where employees can be socially engineered by phone into granting Microsoft 365 access from personal devices; attackers then use built-in cloud interfaces to find targets and hand access to extortion groups.
Fix
Enforce phishing-resistant authentication and conditional access, minimize standing privileges so a hijacked account does little, monitor Graph API and sign-in activity for abuse, and train users specifically against voice-based social engineering.

Surfshark VPN says a misconfigured test server let attackers reach build credentials

VPN provider Surfshark disclosed that attackers accessed an internal engineering test server that a configuration error had left reachable from the internet, along with a proxy server used for content optimization. Surfshark says the exposure was limited to a non-production environment and included service configurations, build-related credentials, system binaries, and portions of code history, but did not reach customer data, VPN traffic, encryption keys, or production systems. The company detected the activity on August 31, contained it by September 2, rotated credentials, revoked tokens, and completed remediation within days. It is a reminder that misconfigured internet-exposed test environments remain a common and avoidable breach path, even at security-focused companies.

Check
Inventory internet-facing assets for exposed test, staging, and engineering servers, remove public access to non-production systems, and rotate any build credentials or tokens that a test environment could expose.
Affected
Organizations with internal test or engineering servers unintentionally reachable from the internet; attackers can obtain build credentials, configurations, and source history, which can seed further compromise even when production data is untouched.
Fix
Keep non-production environments off the public internet, apply production-level access controls to test systems, store credentials in dedicated vaults rather than build environments, continuously scan your external attack surface, and rotate secrets.

CISA flags exploited Cisco, Citrix, Fortinet, and WatchGuard edge flaws

CISA added several actively exploited flaws in internet-facing security appliances to its catalog, ordering federal agencies to patch by September 12. The most severe, CVE-2026-20079 scored 10.0, is an authentication bypass in Cisco Secure Firewall Management Center that lets an unauthenticated attacker run scripts and gain root on the device; Cisco confirmed exploitation since August. A Citrix NetScaler authentication bypass, CVE-2026-19490, saw a surge of attacks on September 8, and a Fortinet FortiOS flaw, CVE-2025-25249, is being used to deliver a remote access trojan. Separately, CISA warned that a critical WatchGuard Firebox firewall flaw is now being exploited in ransomware attacks. Edge appliances remain prime targets.

Check
Immediately patch internet-facing Cisco Secure FMC, Citrix NetScaler, Fortinet FortiOS, and WatchGuard Firebox devices to fixed versions, prioritizing anything reachable from the internet, and hunt exposed appliances for signs of compromise.
Affected
Organizations running affected Cisco Secure FMC, Citrix NetScaler, Fortinet FortiOS, or WatchGuard Firebox appliances (CVE-2026-20079, CVE-2026-19490, CVE-2025-25249); all are exploited, from unauthenticated root access to RAT and ransomware deployment.
Fix
Patch these appliances now given the short federal deadline and active exploitation, restrict management interfaces from the internet, monitor for auth-bypass and script-execution activity, and treat any exposed unpatched device as compromised.

Nearly one in ten exposed LiteLLM AI gateways still accept the example admin key

Researchers at Wiz found that nearly one in ten internet-facing LiteLLM servers still accept "sk-1234," the example administrator key printed in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway that sits between an organization's apps and the model providers it pays for, and that admin key unlocks every stored provider API key; in Wiz's tests it even reached the cloud identity credentials of the host machine. The finding accompanies a cluster of exploited LiteLLM flaws that attackers have used to run code, steal secrets, and deploy crypto miners, with one ransomware group and a Microsoft-documented breach among them. Microsoft's advice is to treat AI gateways as top-tier secrets stores.

Check
Change the LiteLLM admin key immediately if it is still the default sk-1234, which needs no upgrade, and upgrade LiteLLM to 1.84.0 or later to close the exploited code-execution and auth-bypass flaws.
Affected
Organizations running internet-facing LiteLLM gateways, especially with the default admin key or on unpatched versions; an attacker can read every stored provider API key, reach cloud credentials, and sometimes execute code.
Fix
Replace default keys, patch to the latest LiteLLM, take gateways off the public internet, rotate all provider, cloud, and database credentials it can reach, and treat AI gateways as tier-zero secrets stores.

New cPanel flaw lets a mail-privileged hosting account run code as root

cPanel patched a critical flaw that lets an ordinary hosting account with mail privileges take root control of the whole server. Tracked as CVE-2026-67401 and scored 9.9, it is a SQL injection in the EmailTrack mail-tracking feature that lets an authenticated account create arbitrary files and escalate to code execution as root. It affects all supported cPanel and WHM versions. On a shared server, a single cheap hosting plan or one stolen webmail password can lead to full server takeover, exposing every other tenant's sites, databases, and data. It is the third cPanel flaw since late July that turns one authenticated tenant into root, and cPanel published no indicators to hunt for.

Check
Update cPanel and WHM to the patched builds now, review which accounts hold mail-related privileges, and because no indicators were published, hunt broadly for unexpected root processes, files, and hidden accounts.
Affected
Shared-hosting providers and multi-tenant servers running unpatched cPanel and WHM (CVE-2026-67401); an authenticated account with mail privileges can inject SQL, create files, and execute code as root, taking over the entire machine.
Fix
Patch to the fixed builds, restrict mail-related privileges, isolate tenants, monitor for root-level file creation and command execution, rotate credentials on any suspected compromised server, and assume shared servers are one-account-from-root.

Critical Alby Hub flaw lets attackers drain internet-exposed Bitcoin wallets

Alby warned of a critical flaw in older versions of Alby Hub, a self-hosted Bitcoin Lightning wallet that people run on their own computer or server to hold their funds. An attacker who could reach the wallet's management interface over the internet could gain access without permission and send the owner's funds. The flaw affects versions 1.7.0 through 1.18.5, released before August 2025, and was fixed in 1.19.0 and later, with 1.24.0 the current release. Alby says one user has been affected so far and is withholding technical details for now. The core lesson is to never expose a self-hosted wallet's control interface to the public internet.

Check
If you run Alby Hub, remove any public internet access to its management interface first, then update to the current release, and check exposed instances for unauthorized access or unexpected outgoing payments.
Affected
Owners of self-hosted Alby Hub Lightning wallets on versions 1.7.0 through 1.18.5 reachable from the internet; an attacker reaching the management interface could take control of the wallet and send bitcoin.
Fix
Update Alby Hub to the current version, keep the wallet's management interface off the public internet behind a VPN or local network, use strong unique credentials, and monitor for unexpected transactions.

DeepSeek AI agent tool flaw lets an agent disable its own sandbox

Researchers at VulnCheck found a flaw in the DeepSeek Harness, a tool that runs an AI agent's commands inside an operating-system sandbox so an agent handling untrusted files cannot write outside its workspace. Through an authentication bypass using a spoofed host header, an attacker needing no credentials or API key can call the tool's own web interface to invoke privileged commands with full-access permissions, raise the session's approval policy to unrestricted execution, and read every stored conversation. In effect, the sandbox meant to contain the agent can be switched off from outside. It is a reminder that an AI agent's isolation is only as strong as the authentication protecting its control interface.

Check
If you run the DeepSeek Harness or similar agent-sandboxing tools, restrict and authenticate access to their control interfaces, keep them off untrusted networks, and apply vendor fixes for the host-header authentication bypass.
Affected
Deployments using the DeepSeek Harness to sandbox AI agents; an unauthenticated attacker who reaches its control interface can spoof the host header to escalate to full-access command execution and dump conversations.
Fix
Authenticate and lock down agent-sandbox control planes, never expose them to untrusted networks, validate host headers, patch the flaw, and design agent isolation assuming the control interface itself is a target.