Tech News
← Home  ·  All topics

Cisa Kev

2 GoKawiil briefs on this topic

Check Point confirms active exploitation of two VPN gateway flaws

Check Point disclosed that hackers are actively exploiting CVE-2026-85102, a pre-authentication remote code execution flaw in its Security Gateway VPN certificate handling, and CVE-2026-93616, a path traversal bug in its Management web service. The company says the path traversal flaw has been exploited as a zero-day since July 23, while exploitation of the gateway flaw began September 12 using VPNs and proxies to mask attacker origin. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 25, 2026 to patch.

Cisco patches actively exploited zero-day in Identity Services Engine

Cisco disclosed and fixed several critical vulnerabilities in its Identity Services Engine and ISE-PIC products, including CVE-2026-76460, a maximum-severity authentication bypass that attackers are already exploiting in the wild. The flaw lets an attacker send a crafted request to an unguarded API endpoint and slip past ISE's web management interface entirely. CISA added the bug to its Known Exploited Vulnerabilities catalog the same day the patch shipped.