MEFILES · Edition No. 70Today's edition · Archive · RSS
Ten files · One region · Zero illusions
All Digital Front Monitor stories → The full edition of September 23, 2026 →
Root Without Login

Check Point patches pre-authentication root flaw as CISA flags exploited Zyxel switches

Two network-infrastructure fixes landed on 21 September, one of them on management servers that sit at the centre of Israeli, Gulf and Turkish enterprise networks. Neither has a confirmed regional incident attached to it yet.

Check Point fixed CVE-2026-91843 on 21 September, a critical flaw that could let an attacker run code as root on Security Management and Log Servers with no login required, according to Security Affairs, the site run by Pierluigi Paganini. This desk saw only the aggregator’s homepage summary and not the full article, and no exploitation was reported in what we could retrieve. The same day, CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation: a stack-based buffer overflow in Zyxel GS1900 Series switches in which, per the KEV record and Zyxel’s advisory, a LAN-based unauthenticated attacker could execute OS commands through a crafted HTTP request to the affected CGI program. Zyxel has released patches. No actor has been named in anything we saw, and nothing ties either flaw to state activity.

The surrounding week was heavy on infrastructure guidance and light on confirmed infrastructure incidents. NIST issued the initial public draft of SP 800-82r4, its revised Guide to Operational Technology Security, restructured around Cybersecurity Framework 2.0 with expanded material on asset management, monitoring and zero-trust principles across water, transportation and industrial IoT; comments close on 30 November 2026. Pew, publishing on 22 September, reported that dozens of US water utilities have in recent years been forced to take systems offline, operate manually or suspend billing, and that over just a few days this past July the FBI received reports of cyber incidents affecting water systems in at least seven states, while noting that most incidents have not contaminated water or caused sustained outages. The New York State Senate has scheduled a water-security hearing for 1 October at 250 Broadway, with oral testimony by invitation only.

Assessment: The distinction worth holding is between an endpoint flaw and a management-plane flaw. A pre-authentication root primitive on a security-management server is not one compromised box; it is the console that governs the rest, and its consequences typically surface a fortnight later as an incident rather than a patch note. What we cannot tell you is whether any regional regulator moved: we did not reach the Israel National Cyber Directorate, the Saudi NCA or the UAE Cyber Security Council. Two cautions. Zyxel’s KEV listing means exploitation was observed somewhere, not here — the switches are common in small Gulf utility and building-management networks, but that is a plausible exposure, not evidence. And an aggregator headline about US Coast Guard and FBI personnel boarding two oil tankers over shipboard cyber exposure is circulating with no named vessels, dates or primary statement. We are not running it until the Coast Guard says so.

Digital Front MonitorMEFILES tracking
7US states with water-sector cyber incidents reported to the FBI over a few days in July 2026, per Pew
Evidence5 cited sources · Security Affairs · CISA · Security Boulevard · Viakoo and 1 more
The file25 Jul: 2 stories26 Jul: 2 stories27 Jul: 2 stories28 Jul: 2 stories29 Jul: 2 stories30 Jul: 2 stories31 Jul: 2 stories1 Aug: 2 stories2 Aug: 2 stories3 Aug: 2 stories4 Aug: 2 stories5 Aug: 2 stories6 Aug: 2 stories7 Aug: 2 stories8 Aug: 2 stories9 Aug: 2 stories10 Aug: 2 stories11 Aug: 2 stories13 Aug: 2 stories14 Aug: 2 stories15 Aug: 2 stories16 Aug: 2 stories17 Aug: 2 stories18 Aug: 2 stories19 Aug: 2 stories20 Aug: 2 stories21 Aug: 2 stories22 Aug: 3 stories23 Aug: 2 stories24 Aug: 3 stories25 Aug: 3 stories26 Aug: 2 stories27 Aug: 2 stories28 Aug: 2 stories29 Aug: 2 stories30 Aug: 2 stories31 Aug: 2 stories1 Sept: 2 stories2 Sept: 2 stories3 Sept: 2 stories4 Sept: 2 stories5 Sept: 2 stories6 Sept: 3 stories7 Sept: 2 stories8 Sept: 2 stories9 Sept: 2 stories10 Sept: 2 stories11 Sept: 2 stories12 Sept: 2 stories13 Sept: 2 stories14 Sept: 2 stories15 Sept: 2 stories16 Sept: 2 stories17 Sept: 2 stories18 Sept: 2 stories19 Sept: 2 stories20 Sept: 2 stories21 Sept: 2 stories22 Sept: 1 story23 Sept: 2 stories
Digital Front Monitor · 64 editions since 19 July 2026 · 127 stories filed · 2 in this edition · rail shows the last 60