THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗

AT A GLANCE

  • Check Point reports Management Server exploitation dating to July 23, 2026, and probing of a separate Security Gateway flaw shortly after its September 9 patches.
  • F5 BIG-IP APM exposure requires both an APM access policy and an OAuth profile on a virtual server; hotfixes are available, and Rapid7 reports the flaw is in CISA’s Known Exploited Vulnerabilities catalog.
  • WordPress 7.1.2 fixes a flaw affecting versions 4.7.0 through 7.1.1; server-side code execution depends on additional server and theme conditions.
01

Attackers exploited a Check Point management-server flaw before its emergency fix

Check Point says CVE-2026-93616, a critical Management Server vulnerability, was exploited as early as July 23, 2026, prompting emergency fixes. The company also reported that attackers began probing CVE-2026-85102, a pre-authentication remote code execution flaw in Quantum Security Gateway, days after patches were released on September 9.

What changed For the separate Security Gateway flaw, Check Point reports a progression from patch release on September 9 to attacker probing a few days later—not confirmed successful exploitation.

Why it matters Management Server operators face a potential historical-compromise problem as well as a patching task: installing the emergency fix cannot establish whether a server was compromised earlier.

HelpNet Security ↗
02

F5 BIG-IP APM flaw enables unauthenticated code execution in specific configurations

Rapid7 reports that CVE-2026-94127 is a critical heap-based buffer overflow that could let an unauthenticated network attacker execute code on an affected BIG-IP APM virtual server. Exposure requires both an APM access policy and an OAuth profile on that server; Rapid7 says the flaw was added to CISA’s Known Exploited Vulnerabilities catalog on September 22, while it had not confirmed a public proof of concept. F5 has issued hotfixes for affected release trains.

Why it matters Administrators need configuration-level triage rather than treating every BIG-IP installation as equally exposed. The vulnerable combination can put an edge-facing data plane at risk, but the report explicitly excludes control-plane exposure.

What to watch next Rapid7 expects vulnerability checks for Exposure Command, Vulnerability Management and Nexpose in its September 23 content release; availability is a reported next step, not confirmed delivery.

Rapid7 ↗
03

WordPress 7.1.2 fixes critical unauthenticated path-traversal flaw

WordPress 7.1.2 addresses CVE-2026-87902, which can let an unauthenticated attacker make the software load a PHP file from outside the site’s active theme folders. The project says releases 4.7.0 through 7.1.1 are affected; under certain server and theme conditions, the flaw can lead to code execution.

What changed Version 7.1.2 introduces a fix for a vulnerability the project says is present throughout releases 4.7.0–7.1.1.

Why it matters WordPress operators should distinguish broad version exposure from confirmed code-execution exposure: many releases contain the flaw, but the most severe outcome depends on each site's server and active theme.

HelpNet Security ↗
04

Microsoft-led coalition disrupts EvilTokens phishing service linked to 12,000 inboxes

Microsoft and private-sector and law-enforcement partners disrupted EvilTokens, a phishing service that reportedly compromised more than 12,000 inboxes across over 10,000 organizations. With authorization from a U.S. district court, the coalition seized 50 websites used to run the service and disabled more than 150 related domains.

What changed The coalition moved against infrastructure used to operate the service, seizing 50 websites and disabling more than 150 associated domains. That establishes disruption, not permanent elimination of the operation.

Why it matters The reported successful compromises make this a mailbox incident-response issue across thousands of organizations, not simply a campaign of unsuccessful phishing attempts.

HelpNet Security ↗
05

Researcher details unauthenticated heap overflow exploitation in Canon MF753Cdw printer

A Zero Day Initiative researcher describes CVE-2024-0244, an unauthenticated heap-based buffer overflow in the Canon MF753Cdw printer’s fax handling that can lead to an arbitrary free. The researcher says a malformed fax payload can overwrite a pointer, and describes using Canon’s BJNP protocol to store shellcode at a known address and achieve code execution. The post says the underlying overflow cause was not definitively identified.

Why it matters For MF753Cdw operators, leaving the telephone line disconnected does not remove the network fax-processing surface: the researcher found that the printer still accepted fax requests through an HTTP endpoint.

What to watch next The precise cause of the overflow remains unresolved in this account; the proposed heap-object layout is an assumption rather than a confirmed finding.

ZeroDayInitiative ↗
Cybersecurity — September 23, 2026 | Briefing24