Check Point disclosed that hackers are actively exploiting CVE-2026-85102, a pre-authentication remote code execution flaw in its Security Gateway VPN certificate handling, and CVE-2026-93616, a path traversal bug in its Management web service. The company says the path traversal flaw has been exploited as a zero-day since July 23, while exploitation of the gateway flaw began September 12 using VPNs and proxies to mask attacker origin. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 25, 2026 to patch.
bleepingcomputer.com
· 2026-09-23
A developer has released Kev, a family of small decision-making models (0.8B, 4B, and 9B parameters) built on Qwen3.5, inspired by the architecture behind Jev. The models handle yes/no, multiple-choice, and rating questions within a single request and are compatible with TypeSafe's System One API, meaning developers can run Kev locally instead of relying on that hosted service. Full training code, evaluation data, and a web playground are included, and the models run on both CUDA and Apple Silicon hardware.
github.com
· 2026-09-21
Cisco disclosed and fixed several critical vulnerabilities in its Identity Services Engine and ISE-PIC products, including CVE-2026-76460, a maximum-severity authentication bypass that attackers are already exploiting in the wild. The flaw lets an attacker send a crafted request to an unguarded API endpoint and slip past ISE's web management interface entirely. CISA added the bug to its Known Exploited Vulnerabilities catalog the same day the patch shipped.
darkreading.com
· 2026-09-18
CISA announced it will stop publishing its weekly vulnerability summary bulletins starting Sept. 28, directing organizations instead to its Known Exploited Vulnerabilities catalog, security advisories, and vendor alerts. The agency says the change reflects its push for risk-based vulnerability prioritization rather than relying on severity scores alone, amid a surge in disclosed vulnerabilities partly driven by AI-assisted flaw hunting.
darkreading.com
· 2026-09-17