Cyber One Solutions logo.
Get Support

Security Advisory

This Week's Top 5: WordPress Core Targeted Within Hours, Check Point VPN Attacks, and More Security Developments

Published September 29, 2026 · Cyber One Solutions

A critical WordPress core flaw drew exploitation attempts within hours of its September 22 fix and is now confirmed exploited, Check Point confirmed attacks on firewall VPNs and management servers, and Microsoft confirmed exploitation of a SharePoint Server flaw it patched in August. Here are the top five verified developments for small and mid-size businesses, ranked by relevance, exploitation evidence, and urgency.

This brief covers verified security and compliance developments from Sunday, September 20 through Saturday, September 26, 2026, with a research cutoff of Monday, September 28, 2026 at 2:00 p.m. Central. It is the edition for the regular Sunday, September 27 slot, published two days late on Tuesday, September 29. It was a week in which attackers moved from patch to exploit in hours rather than weeks: a critical WordPress core flaw was being probed the same day its fix shipped, Check Point confirmed attacks on the VPN and management layers of its firewalls, and Microsoft confirmed exploitation of a SharePoint Server flaw it had patched six weeks earlier.

Executive Summary and Priorities

Five verified developments met our bar for inclusion this week, each backed by a vendor confirmation of exploitation, a CISA Known Exploited Vulnerabilities (KEV) catalog listing, or both:

WordPress core
an unauthenticated flaw in every supported release line, fixed September 22, with exploitation attempts within hours and confirmed exploitation since.
Check Point firewalls
confirmed attacks on the VPN component of Security Gateway and Spark firewalls, plus a management-server zero-day.
Microsoft SharePoint Server
a code-injection flaw patched in August, now confirmed exploited in on-premises deployments.
Adobe Commerce and Magento
an authorization flaw in online-store software, added to CISA's KEV catalog on September 24.
Zyxel GS1900 switches
a firmware flaw patched in June and now confirmed exploited, usable only by an attacker already on the local network.

How We Ranked This Week's Developments

We ranked these five by how many of the businesses we serve are likely to run the affected technology, the strength of the exploitation evidence (a vendor's own confirmation, a CISA KEV listing, or both), how directly the affected system is reachable from the internet, and how much time remains before a deadline or consequence lands. WordPress ranks first not because it carries the highest severity score this week, but because it is widely used for small-business websites, drew exploitation attempts within hours of disclosure, and is now confirmed exploited. The Zyxel item ranks last because an attacker must already be on your local network to use it. These rankings are editorial judgments, not a measured risk score.

1A Critical WordPress Core Flaw Drew Exploitation Attempts Within Hours of Its Fix

WordPress released version 7.1.2 on September 22, 2026 to fix CVE-2026-87902, which the WordPress security advisory describes as an "unauthenticated path traversal in page-template resolution leading to conditional RCE," rated Critical with a CVSS v4 score of 9.2, according to WordPress's release announcement and the WordPress security advisory GHSA-7hp8-65ch-5whp. CISA added the flaw to its KEV catalog on September 25, 2026, confirming active exploitation, with a September 28, 2026 remediation deadline for federal civilian agencies, which passed the day before this brief published, per CISA's alert. The security firm Patchstack reported seeing the first exploitation attempt at 11:49 UTC on September 22, the same day the fix shipped, and attackers writing files to disk by September 23.

The advisory lists every release from 4.7.0 through 7.1.1 as affected, with fixes backported to each branch, including 7.1.2, 7.0.6, 6.9.9, 6.8.10, and 6.7.9 for the most recent lines and down to 4.7.37 for the oldest. Not every site is exposed to code execution: the advisory says turning the flaw into remote code execution requires an active theme with a top-level folder whose name begins with "page-" (it names the legacy Twenty Twelve and Twenty Fourteen themes and the third-party Neve, Hestia, and Sydney themes) and a server where a readable PHP file such as pearcmd.php exists and the PHP setting register_argc_argv is on. The advisory adds that the default cPanel configuration is affected when PHP older than 8.5 is in use, a common setup for shared business hosting. Those conditions are server details most business owners cannot check themselves, which is why the practical answer is simply to update. WordPress notes that sites supporting automatic background updates will begin updating automatically, but do not assume yours did: confirm the version in the WordPress dashboard under Updates, and if the site was on an older build after September 22, ask whoever hosts it to check for unfamiliar PHP files. Our website design, hosting, and maintenance service includes platform patching and security monitoring for the sites we manage.

2Check Point Confirms Attacks on Firewall VPNs and Management Servers

Check Point published an advisory on September 22, 2026 confirming exploitation of two separate flaws, each rated CVSS v3.1 9.8, per Check Point's security advisory. The first, CVE-2026-85102, is an improper certificate validation flaw in VPN negotiation on Security Gateway and on both centrally and locally managed Spark firewalls. Check Point fixed it on September 9 with no known exploitation at the time, then observed "a wave of exploitation attempts against Spark customers" starting September 12. CISA's KEV entry says the flaw affects gateways using Site to Site VPN or Remote Access VPN and could let an unauthenticated remote attacker execute arbitrary code on the gateway. The second, CVE-2026-93616, is a path traversal zero-day in the Security Management Server web service that lets an unauthenticated attacker upload and execute scripts; Check Point says it observed "a handful of pinpointed attacks on July 23, 2026" and released the fix with this advisory. CISA added both to its KEV catalog on September 22 with a September 25 deadline, per CISA's alert.

This matters to any business whose firewall or remote-access VPN runs on Check Point, including the Spark appliances attackers specifically targeted. Affected releases span multiple R81 and R82 builds, plus R80 for the management flaw, and the exact fixed builds are listed in Check Point's support articles sk1000117 and sk1000171. Because exploitation attempts against the VPN flaw began ten days before this advisory and the management flaw was exploited in July, patching alone does not answer the question of whether you were reached. Check Point recommends reviewing logs for unusual certificate-based Mobile Access logins and for follow-on activity from those sessions, and it published indicators of compromise in sk1000171. We covered an earlier Check Point management flaw in our July brief; two exploited Check Point management flaws in one quarter is a reason to confirm the management interface is not reachable from the internet at all. Our managed ISP and edge security service covers firewall policy and patch management at each site we manage.

3Microsoft Confirms Exploitation of a SharePoint Server Flaw Patched in August

Microsoft updated its advisory for CVE-2026-65660 on September 25, 2026 to state that "Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability," and CISA added it to the KEV catalog the same day with a September 28 deadline, per Microsoft's Security Update Guide and CISA's alert. The flaw is a code injection issue rated Important with a CVSS v3.1 score of 8.8. Microsoft says "an authenticated attacker with low-level access to an affected server could send a specially crafted request to execute code on the server," with no user interaction required.

The fix is not new: Microsoft released it on August 11, 2026. The affected products Microsoft lists are on-premises editions only: SharePoint Server Subscription Edition (KB5002893, fixed build 16.0.19725.20522), SharePoint Server 2019 (KB5002894 and KB5002896, fixed build 16.0.10417.20198), and SharePoint Enterprise Server 2016 (KB5002905 and KB5002906, fixed build 16.0.5565.1001). SharePoint Online in Microsoft 365 does not appear in that list. The risk is concentrated in businesses that still run their own SharePoint server, often a legacy intranet or document system that nobody has touched since a migration was postponed. Because the attacker needs only low-level access, a single compromised employee account may be enough. If your organization runs SharePoint Server, confirm the installed build is at or above the fixed build for your edition, and because the exploitation evidence arrived six weeks after the patch, treat any server that was unpatched in that window as worth a log review. This is the second exploited SharePoint Server flaw we have covered this year, after our July brief. Our Microsoft 365 support team can help you decide whether an on-premises SharePoint server still earns its place or belongs in SharePoint Online.

4An Exploited Adobe Commerce Flaw Puts Online Store Customer Accounts at Risk

CISA added CVE-2026-71362, an incorrect authorization vulnerability in Adobe Commerce and Magento Open Source, to its KEV catalog on September 24, 2026 with a September 27 remediation deadline, confirming active exploitation, per CISA's alert. Adobe fixed the flaw in its August 2026 security bulletin APSB26-92 and rates it CVSS v3.1 9.1, describing a flaw that could let an attacker "gain elevated access to sensitive resources" without any user interaction, according to the NIST National Vulnerability Database entry, which lists Adobe Commerce and Magento Open Source releases up to and including 2.4.9, along with Adobe Commerce B2B, as affected.

This matters to any business that sells online on a self-managed Adobe Commerce or Magento store, because the system at risk holds customer accounts, order history, and the checkout experience. It is less relevant to businesses that sell through hosted platforms that do not run Magento. If you run a Magento or Adobe Commerce store, ask your developer or hosting provider to confirm the APSB26-92 fix is installed and to review admin and customer account activity since mid-August. Card-handling obligations do not pause while a patch waits in a queue; our earlier brief on PCI DSS payment page script requirements explains what online merchants are expected to monitor.

5A Zyxel Switch Flaw Patched in June Is Now Confirmed Exploited

CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series switches, to its KEV catalog on September 21, 2026 with a September 24 deadline, per CISA's alert. Zyxel disclosed and patched the flaw on June 16, 2026, describing it as one that "could allow a LAN-based, unauthenticated attacker" to "potentially execute OS commands via a crafted HTTP request," per Zyxel's security advisory, and Zyxel's score in the NVD entry is CVSS v3.1 8.8.

Affected models are the GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2, GS1900-48, and GS1900-48HPv2 on firmware 2.90 builds ending in ".1)C0" and earlier; each model's fixed build ends in ".2)C0", for example 2.90(AAHL.2)C0 for the GS1900-24. This is a second-stage flaw: an attacker has to reach the switch from inside your network first, through an infected laptop, an unsecured guest port, or a compromised device on the same segment. That is exactly why it matters: switches are rarely on anyone's patch list, and a compromised switch gives an intruder a quiet place to watch or redirect traffic. If you have Zyxel GS1900 switches in a network closet, confirm the firmware against Zyxel's table, and ask whoever manages your network whether the switch management page can be reached from every desk and guest port or only from a restricted management network. Our managed IT service keeps network equipment firmware on the same documented patch cycle as servers and workstations.

Also Added to the KEV Catalog This Week

CISA also confirmed exploitation of flaws in products that fewer small businesses run directly but that a hosting provider, telecom carrier, or larger partner might: F5 BIG-IP APM (CVE-2026-94127) and Arista VeloCloud Orchestrator on-premises (CVE-2026-93952), both added September 22, and WSO2 API Manager and related products (CVE-2026-5430), added September 24. If a provider operates any of these on your behalf, ask them to confirm in writing that the fixes are in place.

Update on a Prior Item: MikroTik RouterOS

Our September 13 brief listed whether CISA would add more of the MikroTik RouterOS flaws disclosed on September 5 to its KEV catalog as a watch item. On September 25, CISA added CVE-2026-67279, an SSH flaw that CISA says "could allow an unauthenticated client to open a session channel and send an exec request" and "can be chained to achieve unauthenticated exploitation of CVE-2026-86060," the privilege-escalation flaw already in the catalog, per CISA's Known Exploited Vulnerabilities catalog. The fixed RouterOS versions are unchanged, per the NVD entry: 6.49.21 (long-term), 7.23.4 (long-term), and 7.24.2 (stable). If you already upgraded after our earlier brief, no new action is needed; if you did not, this is a second confirmed reason to do it now.

Developing After the Coverage Window: Citrix NetScaler

On Sunday, September 27, one day after this brief's coverage window closed, CISA warned that two newly disclosed Citrix NetScaler ADC and NetScaler Gateway zero-days, CVE-2026-88771 and CVE-2026-88772, are being actively exploited and can allow remote code execution, and added both to the KEV catalog with a September 30 deadline and a forensic triage requirement, per CISA's alert. CISA urges organizations to check for signs of compromise and preserve forensic evidence before applying updates. We will rank it fully in next week's brief, but if your business runs NetScaler for remote access, follow Citrix's guidance today rather than waiting.

Do Now

Plan Next

Watch List

The Bottom Line

The common thread this week is time. Three of the five developments involved fixes that had been available for weeks or months before exploitation was confirmed. In the other two, attackers moved within hours or days of a fix, and in Check Point's management flaw, before a fix existed at all. A business that patches on a quarterly rhythm, or only patches the servers and laptops it can see, would have been exposed on every item here. This brief is general security awareness, not a HIPAA, FTC Safeguards, or cyber-insurance compliance service. Cyber One Solutions helps commercial businesses close that gap through managed cybersecurity with monitoring across firewalls, servers, and cloud services, and IT and security assessments that find the websites, stores, switches, and legacy servers an inventory usually misses. If you are not sure where to start, our free cybersecurity risk score is a quick way to see which of this week's gaps may apply to you.

Sources