Check Point patches pre-authentication root flaw as CISA flags exploited Zyxel switches
Two network-infrastructure fixes landed on 21 September, one of them on management servers that sit at the centre of Israeli, Gulf and Turkish enterprise networks. Neither has a confirmed regional incident attached to it yet.
Check Point fixed CVE-2026-91843 on 21 September, a critical flaw that could let an attacker run code as root on Security Management and Log Servers with no login required, according to Security Affairs, the site run by Pierluigi Paganini. This desk saw only the aggregator’s homepage summary and not the full article, and no exploitation was reported in what we could retrieve. The same day, CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation: a stack-based buffer overflow in Zyxel GS1900 Series switches in which, per the KEV record and Zyxel’s advisory, a LAN-based unauthenticated attacker could execute OS commands through a crafted HTTP request to the affected CGI program. Zyxel has released patches. No actor has been named in anything we saw, and nothing ties either flaw to state activity.
The surrounding week was heavy on infrastructure guidance and light on confirmed infrastructure incidents. NIST issued the initial public draft of SP 800-82r4, its revised Guide to Operational Technology Security, restructured around Cybersecurity Framework 2.0 with expanded material on asset management, monitoring and zero-trust principles across water, transportation and industrial IoT; comments close on 30 November 2026. Pew, publishing on 22 September, reported that dozens of US water utilities have in recent years been forced to take systems offline, operate manually or suspend billing, and that over just a few days this past July the FBI received reports of cyber incidents affecting water systems in at least seven states, while noting that most incidents have not contaminated water or caused sustained outages. The New York State Senate has scheduled a water-security hearing for 1 October at 250 Broadway, with oral testimony by invitation only.
Assessment: The distinction worth holding is between an endpoint flaw and a management-plane flaw. A pre-authentication root primitive on a security-management server is not one compromised box; it is the console that governs the rest, and its consequences typically surface a fortnight later as an incident rather than a patch note. What we cannot tell you is whether any regional regulator moved: we did not reach the Israel National Cyber Directorate, the Saudi NCA or the UAE Cyber Security Council. Two cautions. Zyxel’s KEV listing means exploitation was observed somewhere, not here — the switches are common in small Gulf utility and building-management networks, but that is a plausible exposure, not evidence. And an aggregator headline about US Coast Guard and FBI personnel boarding two oil tankers over shipboard cyber exposure is circulating with no named vessels, dates or primary statement. We are not running it until the Coast Guard says so.