← All issues

#CyberWeekly

Sep 11 - Sep 17, 2026
How this newsletter is curated

Two firewall holes, one already used

Two firewall holes, one already used
The lights all read green. The lock does not know that.

Every good trick works because you are watching the wrong hand.

Two of the biggest firewall makers both have a hole that needs no password at all. One of them is still a warning. The other is already being used to deliver ransomware. That difference is the only thing worth reading this week, because it tells you which one you can still get ahead of.

Is this you? If you or your IT provider runs a Check Point firewall, or Cisco's tool for managing firewalls, then yes. Check Point covers three product lines: Security Gateway and Security Management Server for larger offices, and Spark, built for a company about the size that reads this newsletter. The Cisco product is not something you would install yourself. It is the tool many IT companies use to manage every firewall they look after, including yours.

  • Check Point: two flaws, CVE-2026-85102 and CVE-2026-85103, both scoring 9.8 out of 10. An attacker needs no password and no login. Getting in is the whole vulnerability. Fixes have existed since 7 September, as LivePatch Take 24 or a Jumbo Hotfix depending on your version.
  • Nobody has been caught using the Check Point flaws yet, and that is the window that matters. The Dutch national cyber agency, NCSC, is not waiting for proof. It says an unpatched system could be taken over completely and expects that to start soon. A flaw with no working public exploit is the easiest one to close before it becomes one.
  • Cisco is the other half, and it is past the warning stage. On 10 September Cisco confirmed attackers were already inside its Secure Firewall Management Center. CVE-2026-20079 scores the maximum 10 out of 10 and lets someone log in as administrator with no password. CVE-2026-20316 is smaller alone but chains with it.
  • Cisco's own researchers found three separate groups already in real networks. One was stealing logins. One is linked to a Russian government hacking group. The third used the tool's own features to look around first, then deployed Qilin, the same ransomware crew that listed a Belgian furniture chain on its leak site last month.
  • The American cyber agency gave its own agencies until 12 September on the Cisco flaws. That date has passed by the time you read this. It tells you how urgently this is treated elsewhere, not how urgent it still is for you. Fix it regardless of any date.

If you manage your own firewall, check the brand today. If somebody else does, send them both questions: "Do we run Check Point for our firewall or VPN? If so, are we on a version patched since 7 September, and who checked? And do we use Cisco's Secure Firewall Management Center? If so, are the hotfixes for CVE-2026-20079 and CVE-2026-20316 both installed, and did anyone read the logs from before they went in?" That last part only applies to the Cisco one, and it matters: a warning you can close quietly, but a hole already in use means somebody may have walked through before you shut it. A firewall that looks fine from the outside is the whole point of both flaws. Nothing on the box tells you it is exposed. Our guide to choosing and checking a firewall covers the basics, and what to ask whoever manages yours has the rest of the list. On the Cisco half, why your supplier's tools are your risk too explains why it is not somebody else's problem.

BleepingComputer: Dutch NCSC warns Check Point VPN flaws exploitation is imminent →

Worry about the quiet supplier

- by Patch, our friendly house bot

Worry about the quiet supplier
The good ones show you how the trick works.

"Check Point went looking inside its own product, found the hole above, and told everybody."

"Nobody made them do that. They could have folded the fix quietly into the next release and none of us would ever have known. Instead they published it, scored it 9.8 out of 10, and said plainly that no password is needed to walk through. That is the only reason you heard about it before somebody used it on you."

"So the supplier who sends you a frightening warning is not the one I would worry about. The one I would worry about is the supplier whose software you have run for six years without ever getting a single warning from them."

"I do not know what is inside the products that never write to me. Neither do you. Silence from a supplier feels like safety, and it is not evidence of anything at all."

"So this week, write down the software your business could not work without for one day. Then ask which of those suppliers has ever told you about a hole in their own product. If one never has, that is not a clean record. It is a blank page."

— Patch, your friendly house bot

Judging a supplier whose code you cannot read yourself is its own job. What to expect from a supplier sets out the questions worth putting to them.

Patient files stolen from a GP practice

Patient files stolen from a GP practice
The drawer still closes. That was never the problem.

Not every disappearing act happens on a stage.

A doctor's practice in Gouda, just over the Dutch border, had patient files stolen this week. Huisartsencentrum Klein Iterson said people who should not have had access got into part of its systems, and that personal data and parts of patients' medical files were viewed or taken.

Is this closer to your risk than a hospital headline? Klein Iterson is a GP practice: a handful of staff, one shared system, not a hundred-bed hospital with a security team. If your business is a medical, legal, financial, or notary practice holding other people's private records, this is closer to your size than most ransomware stories get.

  • The stolen data includes names, birth dates, addresses, phone numbers, and for some patients their national identification number. That last one, the BSN in the Netherlands, is the same kind of number as the Belgian rijksregisternummer: hard to change, and useful for identity fraud for years.
  • The ransomware group LockBit5 claimed responsibility and has already published stolen documents online. How the attackers got in was not made public.
  • No new Belgian company appeared on a public ransomware leak site this week, the third week running. We checked the tracker rather than assumed: 178 Belgian organisations logged in total, and the newest entry is still takt.be on 27 August. Three quiet weeks are real, and they still are not proof that nothing is happening quietly.

If your practice or office holds other people's private records, this is the one question worth asking this week: "If someone who should not have access logged in tomorrow, would anything actually tell us?" Most small practices answer honestly with "probably not," and that answer is the whole risk. Our guide on who should be able to see what is the place to start, and security for healthcare and medical practices covers the sector specifics.

Security.NL: patient data stolen in hack of Gouda GP practice (Dutch) →

Platform Spotlight

We build your compliance report for you

We build your compliance report for you
Everything an auditor asks for, in one place, not four.

No smoke, no mirrors, just the paperwork.

An auditor's first question is usually the same one: show me your Statement of Applicability. It is the single document that lists every control you are supposed to meet, whether you meet it, and why not if you do not. Building it used to mean screenshots and a spreadsheet. Now it is generated straight from your own control register.

  • One document, not a folder. Every control you are in scope for, its status, and the evidence behind it, laid out the way an assessor actually reads it.
  • Your risk register now draws from every framework you are active on, not just your main one. If a client questionnaire asks a GDPR question and you only run CyFun, that question is now answered from the same register instead of a second spreadsheet.
  • Every risk now shows which controls are supposed to treat it, and whether they actually hold. Until this month a control could read as covered here with nothing behind it. We shipped that fix on 11 September, and this is the same honesty applied to risk.

Try this: open your risk register and pick one risk marked as treated. Read which controls are named against it, and whether their own evidence is current. That is exactly what an assessor will do to you, done in advance, by you. How risk assessment works explains the mechanics, and preparing for an audit is what this whole thing is for.

Try it now →


Never miss an issue

Get #CyberWeekly delivered to your inbox every Thursday.

Or use our RSS feed

TJ

Tom Janssens

Editor, #CyberWeekly, LinkedIn

Questions or feedback? Contact us. We read every message.

easycyberprotection.com