The news
Edge device exploitation, meaning attacks on internet-facing firewalls, VPNs and gateways, produced a run of urgent security warnings in September 2026. Between September 8 and 21, vendors and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed attacks on gear from Check Point, Cisco, Citrix, Fortinet, MikroTik and Zyxel.
Check Point Software (CHKP) shows how fast the window closes. Its advisory for CVE-2026-85102, an authentication bypass and remote code execution flaw in remote access and site-to-site VPN rated 9.8 out of 10, was created on September 7, and BleepingComputer reported fixes shipped on September 9. BleepingComputer reported on September 12 that the Dutch National Cyber Security Centre expected exploitation attempts soon. Check Point's advisory now states the flaw is actively exploited on Spark Firewalls as of September 12. Affected versions include several that are past end of support, from R80 through R81.10.
CISA's Known Exploited Vulnerabilities catalog, the federal list of flaws with evidence of active attack, added a Citrix NetScaler authentication bypass, a Fortinet heap overflow and a Cisco Firewall Management Center authentication bypass on September 9, two MikroTik RouterOS flaws on September 10, the Cisco Secure Email Gateway zero-day on September 14 and a Zyxel switch flaw on September 21. Each carried a federal remediation deadline of three days. Security Affairs reported that the Fortinet flaw was being used to install a remote access trojan on FortiGate devices.
Patching alone may not be enough. Hackread reported on September 10 that Sophos analyzed Linux malware on F5 (FFIV) BIG-IP Access Policy Manager devices that injects a PHP web shell into Apache's memory while leaving files on disk unchanged, defeating file integrity checks. Cisco's advice for compromised virtual email gateways is to rebuild them and renew credentials and cryptographic keys.
Japan's Digital Agency shows the lag that follows. On September 11 it disclosed that attackers used a VPN device vulnerability to reach its Government Solution Service, exposing about 246,000 records. Suspicious access was detected June 25 and the VPN intrusion identified July 9. SecurityWeek reported the agency said the flaw had been publicly disclosed before the attack was confirmed.
The numbers
- Check Point CVE-2026-85102 severity
- CVSS 9.8
- Federal deadline for edge flaws added Sept 9–21
- 3 days
- Records exposed via VPN flaw at Japan's Digital Agency
- About 246,000
- Time from detection to public disclosure (Digital Agency)
- June 25 to Sept 11
Why CEOs should care
For boards, the question is capacity. Can the company patch an internet-facing firewall or VPN within three days of an exploitation warning, including weekends? Ask for an inventory of every edge device, its software version and support status, and the name of the person accountable for each. Check Point's affected list includes end-of-support releases, which is a reminder that unsupported network gear is a standing liability, not a deferred expense.
For CISOs, treat an exploited edge flaw as a possible breach, not a maintenance ticket. Patch, then look for signs of prior compromise: new accounts, configuration changes, unexpected processes and outbound connections. The F5 memory-resident web shell and Cisco's rebuild guidance both show that a clean file system does not prove a clean device. Send appliance logs to systems attackers cannot tamper with, and rehearse rebuilding a gateway from a known-good image.
For CFOs, fund the unglamorous parts: replacement of end-of-support appliances, spare capacity for emergency change windows, and retainer hours with an incident response firm that can examine appliances. These costs are small next to a breach like the one Japan's Digital Agency took months to disclose.
The bigger picture
Attackers favor edge devices because they sit on the internet, run with high privileges and usually lack the endpoint detection software that would flag an intruder on a laptop or server. The pace did not slow after September 21: CISA added further Check Point, F5 and Arista flaws on September 22 and two Citrix NetScaler zero-days on September 27. The September record suggests the perimeter deserves at least as much executive attention as laptops and cloud accounts. Edge gear is also the least visible to executives: it is bought as infrastructure, run by network teams and often managed by third parties, which makes ownership and patch accountability easy to lose.
What’s next
Watch whether Check Point confirms exploitation beyond Spark Firewalls, and whether vendors publish indicators that help customers check for compromise, not just patches. Companies should also expect regulators and insurers to ask how fast they remediate known exploited flaws, using CISA's list as the yardstick.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







