{
  "slug": "2026-09-21",
  "date": "2026-09-21",
  "updated": "2026-09-23",
  "title": "Run a Check Point firewall for VPN? Patch it now",
  "intro": "This week's top item: if your office uses a Check Point Security Gateway or Spark Firewall for VPN access, patch it now. Check Point says criminals are already breaking into Spark customers worldwide using a flaw in how the firewall checks VPN certificates — no password needed. Zyxel GS1900 network switches also need a firmware update for a flaw criminals are using, though that one only matters if an attacker is already on your office network. If you don't run either product, there's nothing here to act on this week. If you missed last week's Cisco, Acronis and freelance-hiring items, they're on the previous week's page.",
  "quietWeek": false,
  "items": [
    {
      "id": "check-point-spark-vpn-certificate-rce",
      "rank": 1,
      "published": "2026-09-22",
      "title": "Run a Check Point firewall for VPN? Patch it now",
      "summary": "Check Point Security Gateway and Spark Firewall — Check Point's line built for small and medium offices — share a flaw in how they check certificates during VPN connections. It lets an attacker connect without a password and run their own commands on the firewall. Check Point published a fix on 9 September 2026, but from 12 September it began seeing criminals actively exploiting the flaw against Spark customers worldwide, using forged VPN certificates from anonymised infrastructure. US cyber security authorities added it to their must-patch list on 22 September.",
      "whoItAffects": "Businesses running a Check Point Security Gateway or Spark Firewall configured for Site-to-Site or Remote Access VPN. Spark is Check Point's product line aimed specifically at small and medium offices, so this is worth checking even if you've never dealt with Check Point's larger enterprise gear. If your firewall is a different brand, or you don't use VPN on it, skip this one.",
      "action": "Ask your IT provider: \"Do we run a Check Point Security Gateway or Spark Firewall for VPN, and has it been updated with the fix Check Point released on 9 September 2026 for CVE-2026-85102?\"",
      "prevention": {
        "e8": "Patch applications",
        "ism": "System patching"
      },
      "sourceKind": "kev",
      "cves": [
        "CVE-2026-85102"
      ],
      "cwes": [
        "CWE-295"
      ],
      "links": [
        {
          "label": "CISA KEV: Check Point certificate validation flaw",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-85102"
        },
        {
          "label": "Check Point security advisory",
          "url": "https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616"
        }
      ]
    },
    {
      "id": "zyxel-gs1900-switch-buffer-overflow",
      "rank": 2,
      "published": "2026-09-21",
      "title": "Own a Zyxel GS1900 network switch? Update its firmware",
      "summary": "Zyxel GS1900 switches are compact managed network switches that link computers, phones and Wi-Fi access points in many small offices. The US Cybersecurity and Infrastructure Security Agency (CISA) has added a flaw in their web management page to its list of vulnerabilities criminals are already using. Someone on the office network — a compromised laptop, a rogue device or a Wi-Fi guest — can send the switch a single crafted request and potentially run their own commands on it, with no password needed. Zyxel has released fixed firmware for every affected model and lists no workaround.",
      "whoItAffects": "Businesses using a Zyxel GS1900 series switch (models GS1900-8, -8HP, -10HP, -16, -24, -24E, -24EP, -24HPv2, -48 and -48HPv2) — usually fitted by an IT provider or electrician and rarely looked at again. The attacker must already be on your network, so this is not a risk from the internet alone. If your switches are another brand, or you have no dedicated switch, ignore this one.",
      "action": "Ask your IT provider: \"Do we have any Zyxel GS1900 switches, and have they been updated to the fixed firmware Zyxel released for that model in its June 2026 advisory?\"",
      "prevention": {
        "e8": "Patch applications",
        "ism": "System patching"
      },
      "sourceKind": "kev",
      "cves": [
        "CVE-2026-7273"
      ],
      "cwes": [
        "CWE-121"
      ],
      "links": [
        {
          "label": "CISA KEV: Zyxel GS1900 switch flaw",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-7273"
        },
        {
          "label": "Zyxel security advisory",
          "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026"
        }
      ]
    }
  ]
}
