NCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected
Dutch NCSC warns of two critical CVSS 9.8 Check Point VPN flaws enabling unauthenticated remote code execution, urging immediate patching before mass exploitation.
The Dutch NCSC warned that CVE-2026-85102 and CVE-2026-85103, both rated 9.8 CVSS, allow unauthenticated remote attackers to execute arbitrary code on Check Point Quantum Security Gateway, Spark Firewall, and Security Management Server deployments when VPN is enabled. CVE-2026-85102 stems from improper certificate trust validation during VPN negotiation, while CVE-2026-85103 is a heap-based buffer overflow in ASN.1 certificate decoding. Check Point shipped emergency updates on September 9, 2026, including R82.10 Take 44, R82 Take 126, and R81.20 Take 166 or later, plus LivePatch for eligible systems. No public exploit code exists yet, but the NCSC rates exploitation likelihood high and recommends restricting UDP ports 500 and 4500 to known peers as a stopgap.
GitLab’s critical flaw is already drawing internet-wide probes
GitLab patches two critical flaws (CVE-2026-85706 CVSS 10.0, CVE-2026-87719) as WatchTowr observes internet-wide probing of the unauthenticated file-read bug.
GitLab released emergency patches for two high-severity flaws in Community and Enterprise Editions, urging self-managed operators to upgrade immediately while saying its hosted and Dedicated offerings are fixed or unaffected. CVE-2026-85706 (CVSS 10.0) is a path traversal in the repository commits interface that lets unauthenticated attackers read any file on the server and affects releases 18.7 through 19.1.8 plus the 19.2 and 19.3 lines before patching. CVE-2026-87719 (CVSS 9.9, Enterprise Edition only) lets a logged-in Duo Chat user hide a command in a request that triggers Advanced Search settings and password disclosure. WatchTowr Labs reported it is already watching probes that can trigger the path traversal flaw in a single HTTP request, though CISA had not added either issue to the KEV list as of Friday afternoon.
Cyber Security News
Microsoft's September Patch Tuesday fixes nearly 1,000 vulnerabilities; CISA warns two of the flaws are being actively exploited.
Microsoft's September 2026 Patch Tuesday release addresses close to 1,000 vulnerabilities, with CISA warning that two of the bugs are being actively exploited. The Record's homepage digest also lists briefs including a US offer of $10 million for information on an Iranian hacker accused of attacking critical infrastructure and a leak of health data on more than 9.5 million people from the Aesto record system. Additional briefs cover a Russian suspect's extradition to the US for bank account takeovers, US-British coordination on scam center takedowns, G7 guidance on quantum cyber threats, a large DDoS attack on Norwegian public services, and Slovenian casinos reopening after a cyberattack.
Three 10.0 security flaws fixed across Ubiquiti’s UniFi line
Ubiquiti patches 22 UniFi vulnerabilities, 21 rated critical including three CVSS 10.0 flaws enabling unauthorized access.
Ubiquiti disclosed and patched 22 vulnerabilities, 21 rated critical and three assigned the maximum CVSS 10.0 score: CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554. All three involve improper access control that could let attackers gain privileges, while other flaws permit authentication bypass or arbitrary command execution. All but one of the 22 affect the UniFi product line. The company did not confirm whether any were exploited before patching.