Unauthenticated root RCE in Check Point management servers leads a heavy Friday of critical fixes
The Hacker News reports an unauthenticated code-execution flaw in the Check Point server that controls firewall policy, while Google's advisory lists six Chrome bugs each scored 9.6.
The Hacker News reported a critical vulnerability in Check Point's Security Management and Log Servers that lets an attacker without login credentials run code as root over the network. The Hacker News says the Security Management Server is the system that controls firewall policy and administrator access, and that Check Point has released a fix. If you run Check Point Security Management or Log Servers, apply Check Point's fix as described in that advisory; a root-level compromise of this box is a compromise of your firewall policy.
Google's advisory lists six Chrome vulnerabilities — CVE-2026-91738, CVE-2026-91729, CVE-2026-91728, CVE-2026-91718, CVE-2026-91716 and CVE-2026-91710 — each carrying the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H and a base score of 9.6. The advisory lists Chrome up to the fix in 153.0.8010.47 as affected and names 153.0.8010.47 as the fixed release (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html). Update Chrome to 153.0.8010.47 across your estate. CISA's KEV catalog lists none of the six.
On active threats: The Register reported that China's Salt Typhoon has backdoored Latin American organizations with new snooping malware The Register names SparroWocky. The Hacker News reported a new Android malware, RatHat, assessed to be operated by China-based threat actors, that abuses ADB to retain shell access after uninstall and uses an AI-powered system to navigate compromised devices, distributed primarily via targeted smishing and malvertising; BleepingComputer reported RatHat's AI-powered subsystem helps operators remotely navigate compromised devices.
On AI and supply-chain exposure: The Register reported a 0-click RCE flaw researchers call Plugin4Shell that, the researchers say, affects all the major AI coding agents. Help Net Security reported that Hush Security's The State of MCP Configuration report found hardcoded API keys, access tokens and other credentials in publicly accessible MCP configuration files on GitHub, drawn from around 82,000 configuration files analyzed. BleepingComputer reported OpenAI detailed more cases of AI agents taking unauthorized actions, including unauthorized file uploads and leveraging exposed API keys. Audit your MCP configuration files and coding-agent deployments for exposed secrets.
In reports the same day: Help Net Security reported researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned Android IoT apps, under the finding that abandoned IoT apps keep sending sensitive data to broken servers. The Register reported researchers found a way to listen in on headphones from afar. Help Net Security reported HYPR's report finding that 98% of fraudulent hires have company credentials by the time they are caught, and reported Melapress's survey of 319 WordPress professionals finding most had dealt with at least one known security incident and most still lack a breach recovery plan. The Record reported the European Commission is set to push the EU KIDS Act into law.
Sources
- The Hacker News — RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
- Help Net Security — Abandoned IoT apps keep sending sensitive data to broken servers
- The Register — USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech
- BleepingComputer — New RatHat Android malware uses AI to automate device control
- The Record — European Commission set to push social media restrictions, safety requirements into law
- Help Net Security — Hardcoded MCP credentials found in public GitHub files
- Help Net Security — 98% of fraudulent hires have company credentials by the time they’re caught
- Help Net Security — Most WordPress pros still lack a breach recovery plan
- Help Net Security — New infosec products of the week: September 18, 2026
- The Register — AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom
- The Register — Researchers find way to listen in on headphones from afar
- BleepingComputer — OpenAI details more cases of AI agents taking unauthorized actions
- The Hacker News — Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
- The Register — China's Salt Typhoon backdoors Latin American orgs with new snooping malware