Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

2026-09-22T19:23:59Z•bfa20ac4afef54a1b40279f5324e5cebbd614c50e6551bf7f1d665d75e30ddd3
CVE-2026-65660CVE-2026-7273CVE-2026-89775CVE-2026-90898CVE-2026-93485CVE-2026-93616CVE-2026-93952active-exploitationai-securitycredential-theftlinuxmalwaremicrosoft-sharepointnetwork-appliancesnorth-koreanpmphishingransomwareremote-code-executionsidecopysupply-chain-securitythreat-intelligencevirtualizationvulnerabilitywindowswordpresszero-day

What happened

A September 22, 2026 security-news digest covering multiple actively exploited and critical vulnerabilities, malware campaigns, supply-chain attacks, phishing operations, and enterprise security threats. The highest-risk items include unauthenticated remote code execution in Bifrost (CVE-2026-90898), actively exploited VeloCloud Orchestrator and Check Point management-server flaws, Linux ARM64 KVM host-memory access, SharePoint authenticated RCE, WordPress RCE issues, and Zyxel/Veeam exploitation. The digest also reports malicious npm packages, credential theft, endpoint-defense evasion, North

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
bfa20ac4afef54a1b40279f5324e5cebbd614c50e6551bf7f1d665d75e30ddd3
Enrichment time
2026-09-22T19:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.