Thursday, September 10, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Enterprise edge and management infrastructure dominate the day's disclosures, with Check Point Quantum Security Gateway, Dell Secure Connect Gateway, and WebPros cPanel all carrying critical remote-exploitation flaws. Yesterday's disclosures produced 11 critical CVEs (down 77 percent from 47 the prior day) and 30 high-priority CVEs (down 72 percent from 109), a total of 41 tracked vulnerabilities. CVE-2026-87827 (CVSS 10) affects KGUARD DVR devices, CVE-2026-67401 (CVSS 9.9) affects WebPros cPanel, and CVE-2026-19583 (CVSS 9.9) affects Rapid7 Velociraptor, an incident response agent deployed with broad endpoint access. Nine vulnerabilities have confirmed active exploitation, including flaws in Citrix NetScaler ADC, Cisco Secure Firewall Management Center, Adobe Commerce, and N-able N-central, a pattern consistent with continued targeting of remote access and managed service tooling. Prioritize internet-facing gateways and administrative consoles: inventory exposed Check Point, Citrix, and Cisco management interfaces, restrict them to trusted management networks, and confirm fix status for each product in the vendor's own advisory before scheduling maintenance windows.

  • Check Point Quantum Security Gateway and Quantum Security Management affected by two CVSS 9.8 flaws (CVE-2026-85103, CVE-2026-85102), alongside Dell Secure Connect Gateway 5.0 (CVE-2026-80172)
  • 11 critical CVEs (CVSS 9.0+), down 77 percent from 47 the prior day
  • 30 high-priority CVEs (CVSS 7.0-8.9), down 72 percent from 109 the prior day
  • Remote code execution and authentication bypass dominate, spanning security gateways, DVR firmware (CVE-2026-87827, CVSS 10), and hosting control panels (CVE-2026-67401, CVSS 9.9 in cPanel)
  • Check first: Check Point Quantum gateways, Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center, Rapid7 Velociraptor, and WordPress sites running the Drag and Drop File Upload for Elementor Forms plugin (CVE-2026-18351)
  • 9 vulnerabilities have confirmed active exploitation, covering Citrix NetScaler, Cisco FMC, Fortinet FortiOS, Adobe Commerce, N-able N-central, Google Chrome, and Microsoft Windows

Immediate action: Network security appliances and remote management platforms need attention first: Check Point Quantum, Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center, Fortinet FortiOS, and N-able N-central all appear in today's critical or actively exploited sets, and their administrative interfaces should be restricted to trusted networks where patching cannot happen immediately. Browser and endpoint updates for Google Chrome and Microsoft Windows should follow through normal accelerated channels. Confirm the fix status and affected version ranges for each product in the vendor's own advisory before planning remediation.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation