ITSECURITY.GURU

ITsecurity Daily

Daily Briefing

CISA flags four actively exploited flaws — in Check Point, Arista, and F5 gear — as WordPress and Chrome ship urgent fixes

Good morning. CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation. Per CISA, the four affect Check Point (an improper certificate validation flaw and a path traversal flaw across multiple products), Arista VeloCloud Orchestrator (improper input validation), and F5 BIG-IP APM. If you run any of these, prioritise them.

The Check Point entries connect to a separate disclosure. The Hacker News reported that Check Point warned attackers exploited a previously unknown flaw in its Security Management Server in a handful of targeted attacks on July 23. The Hacker News says the flaw lets an attacker who can access the server's web service run scripts on it without logging in, and that Check Point released a fix on September 2.

WordPress patched a critical core flaw. The Hacker News reported that the flaw lets an attacker with no account make a site load a PHP file from outside its theme folders, and on some servers run their own code; the fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch.

Read the full briefing →

Zoom out: Three of the day's items — Check Point's management-server flaw, a campaign against ZyXEL switches, and a PeopleSoft breach claim — turn internet-facing infrastructure against the organisations that run it.

Vulnerability in focus

CVE-2026-93374 — Google. CVSS 9.6

Affected: chrome.

What to do: Follow the vendor advisory for the fixed release and any interim mitigation.

Elsewhere

  • SecurityWeek: Check Point Patches Exploited Management Server Zero-Day Read it
  • Help Net Security: Prismor: Open-source runtime control plane for AI agents Read it
  • Help Net Security: Product showcase: Scamwise checks the red flags before you take the bait Read it
  • Help Net Security: Nearly two-thirds of tested websites fail every bot test Read it
  • Help Net Security: NetBSD 10.2 security fixes close a remote kernel bug in ipfilter Read it
  • BleepingComputer: Rogue external MFA providers can steal passwords during logins Read it
  • BleepingComputer: Chinese hackers exploit multiple technologies to steal govt data Read it
  • CISA: CISA Adds Four Known Exploited Vulnerabilities to Catalog Read it
  • The Record: Canadian regulator opens probe of IDScan for allegedly violating data privacy laws Read it
  • The Hacker News: Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials Read it
  • The Hacker News: WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Read it
  • The Hacker News: Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks Read it

Sources

Every briefing is on the site, with the advisory record behind it. All briefings

You are receiving this because you subscribed at itsecurity.guru.

Headlines from other outlets belong to them; each one credits its outlet and leads to their own report.

All editions from ITsecurityNews