Here are today’s top cybersecurity stories for Tuesday, September 22, 2026.
Check Point Patches Actively Exploited Management Server Zero-Day
Check Point released emergency fixes for CVE-2026-93616, a critical unauthenticated flaw combining directory traversal with unsafe file-upload handling in its Security Management Server, Multi-Domain Security Management Server, Log Server, and SmartEvent products. The company confirmed targeted attacks against a small number of customers beginning July 23, months before the September 22 patch, and recommends restricting management-server access to trusted IP addresses as an interim step. BleepingComputer
VeloCloud Orchestrator Flaw Rated CVSS 10.0 Under Active Exploitation
Arista Networks confirmed active exploitation of CVE-2026-93952, an input-validation flaw in on-premises VeloCloud Orchestrator deployments configured for certificate-based authentication between Edge devices and the orchestrator. Fixed releases are available for the 5.2 and 6.4 branches, while patches for the 6.1 and 7.0 branches remain pending as of September 22. The Hacker News
CISA Orders Federal Patch for Exploited Zyxel Switch Flaw After Chinese-Speaking Actor Compromises Nearly 1,000 Devices
CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series switches, to its Known Exploited Vulnerabilities catalog and set a three-day remediation deadline for federal agencies. Researchers tracked a suspected Chinese-speaking actor exploiting the flaw alongside a dozen other product vulnerabilities to exfiltrate hashed credentials and configuration data from 996 switches across 48 countries, with more than half of the compromised devices still using factory-default passwords. Help Net Security
D-Link Warns of Unpatched Maximum-Severity Flaw in Legacy Router Line
D-Link disclosed CVE-2026-86296, a maximum-severity stack-based buffer overflow in the DHCP server component of its DIR-822A routers, after a researcher published proof-of-concept exploit code. No patch exists at time of writing, and the vendor is still confirming affected hardware revisions and lifecycle status. GBHackers
Microsoft-Led Operation Dismantles AI-Powered Phishing Service Tied to 12,000 Account Compromises
Microsoft’s Digital Crimes Unit, working with Cloudflare, Coinbase, OpenAI, and other partners, obtained a US federal court order to disrupt EvilTokens, a phishing-as-a-service platform which compromised more than 12,000 Microsoft accounts across over 10,000 organizations since February. UK police arrested two men in London suspected of administering the service, which Microsoft says used artificial intelligence at every stage of its device-code phishing attacks. BleepingComputer
ShinyHunters Claims FBI Breach Through New Oracle PeopleSoft Zero-Day
The ShinyHunters extortion group claims it exploited an undisclosed Oracle PeopleSoft vulnerability to gain remote code execution on an FBI server and move into other bureau-managed infrastructure, allegedly stealing two to three terabytes of employee and applicant data. As of September 22, the FBI, Oracle, and AWS have not confirmed the claims, and no independent evidence of the alleged zero-day has surfaced publicly. BleepingComputer
French Security Firm CrowdSec Confirms Theft of 170 Private GitHub Repositories
CrowdSec disclosed an attacker used an OAuth token stolen from a former employee’s compromised computer, infected via the Shai-Hulud npm worm through the TanStack supply-chain attack, to copy 170 private GitHub repositories on May 22. The company discovered the breach only after the stolen data surfaced on an underground marketplace in mid-September and acknowledged it had neither revoked the departed employee’s access nor deployed endpoint detection on developer machines. The Hacker News
Researcher Demonstrates Mac Backdoor Flaw in Meta’s Muse AI Assistant
Security researcher Patrick Wardle published proof-of-concept code showing malware already running on a Mac redirects Muse’s dictation traffic to attacker-controlled infrastructure through an undocumented preference setting, exposing dictated prompts, injecting attacker instructions the assistant trusts, and capturing account tokens. The flaw requires code execution on the Mac first, achievable through social-engineering techniques such as ClickFix, and remains unpatched at time of writing. The Hacker News
Researcher Behind String of Windows Defender Zero-Days Reveals Identity, Releases New Exploit
Security researcher Abdelhamid Naceri, previously known online as Nightmare Eclipse, revealed his identity and released BigDiskBuster, a new zero-day exploit blocking Microsoft Defender Antivirus from installing platform and intelligence updates on all supported Windows versions. The release continues a string of nearly a dozen Defender and BitLocker zero-days Naceri has published since April amid an ongoing dispute with Microsoft over his 2025 termination. BleepingComputer
Stay tuned for today’s in-depth analysis posts.






