Skip to content
Security & Trust

Critical Flaws Emerge in Cisco, Check Point Security Gear

Cisco and Check Point patched critical bugs as a VPN exploit breached Japan's Digital Agency, exposing 246,000 records.

W
WebPulse Newsroom
AI-assisted · 3 min read
Share on X LinkedIn
Critical Flaws Emerge in Cisco, Check Point Security Gear

Photo: Brett Sayles / Pexels

Key finding

Cisco ISE flaw under active exploitation: CVSS 10.0 (CVE-2026-76460) (Source: Check Point Research Threat Intelligence Bulletin (Sept 21, 2026))

Same Week, Three Points of Failure at the Perimeter

In its threat intelligence bulletin for the week of September 21, Check Point Research documented a run of incidents that share a common location rather than a common actor: the network and security appliances organizations rely on to control who gets in. Cisco disclosed two critical vulnerabilities in its access-control and email security products. Check Point issued a fix for a flaw in its own management servers. And Japan's Digital Agency confirmed a breach that started with an exploited VPN appliance. None of these are connected, but together they point to where exploitation pressure is currently concentrated: the layer meant to keep attackers out.

Cisco's Access Control and Email Gateway Flaws

Cisco disclosed two critical vulnerabilities affecting Identity Services Engine (ISE), which governs network access policy, and Secure Email Gateway, which filters enterprise mail. One of the two, CVE-2026-76460, carries the maximum possible severity score and is already being exploited, according to Cisco. It lets an attacker who has not authenticated reach the system's management interface — the control layer that normally requires credentials and governs policy across the entire deployment.

CVSS 10.0 (CVE-2026-76460)
Cisco ISE flaw under active exploitation
Source: Check Point Research Threat Intelligence Bulletin (Sept 21, 2026)
CVSS 9.8 (CVE-2026-76461)
Secure Email Gateway flaw severity
Source: Check Point Research Threat Intelligence Bulletin (Sept 21, 2026)

Check Point's Own Management Servers Carry a Root-Level Bug

Check Point released a fix for a vulnerability in its Security Management and Log Servers, affecting versions R80 through R82. The flaw sits in the login process, where a stack overflow can be triggered before a user ever authenticates, allowing a remote attacker to execute code with root privileges. Security management servers typically hold policy configuration and logs for an organization's entire firewall estate, which makes a pre-authentication, root-level flaw in that layer one to schedule ahead of a routine patch cycle rather than behind it.

CVSS 9.8, unauthenticated remote code execution as root (CVE-2026-91843)
Check Point Management/Log Server flaw
Source: Check Point Research Threat Intelligence Bulletin (Sept 21, 2026)

A VPN Flaw Already Produced a Breach

The same bulletin recorded a confirmed breach at Japan's Digital Agency, which operates the Government Solution Service used across multiple ministries. Attackers reached the system by exploiting a vulnerability in a VPN appliance, exposing records tied to government officials and contractors. Financial information was not affected, but the incident is a concrete illustration of what an unpatched perimeter access flaw can produce once it moves from advisory to exploitation.

Approximately 246,000 records, including names and contact details
Records exposed in Japan Digital Agency breach
Source: Check Point Research Threat Intelligence Bulletin (Sept 21, 2026)

What to Ask Your Team

For organizations running any of these products, the immediate questions are procedural rather than technical. Confirm whether ISE, Secure Email Gateway, and Check Point Security Management or Log Servers are inventoried against their current patch level today, not at the next scheduled maintenance window. Ask what compensating controls exist if patching a management-plane device requires downtime that hasn't yet been booked. And ask whether VPN and remote-access appliances — the entry point in the Japan Digital Agency incident — sit on the same expedited patch track as internet-facing applications, since in many environments they do not.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Check Point Research.

Share this insight