What you need to know today.
Critical vulnerabilities disclosed in Check Point, Apple, IBM, and Microsoft products, alongside numerous router and Cisco email security flaws.

A critical stack overflow vulnerability in Check Point's security products allows unauthenticated remote attackers to execute arbitrary code with root privileges. This flaw, identified as CVE-2026-91843, stems from an issue during the login process and poses a significant risk to the integrity of affected systems. Details on patches or mitigations are not yet available, but the severity warrants immediate attention from security teams managing Check Point environments.
Apple has released a sweeping set of security updates addressing numerous vulnerabilities across its operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Among the critical flaws patched are CVE-2026-84609, a permissions issue in iOS, iPadOS, macOS, tvOS, visionOS, and watchOS fixed by improved path validation, and CVE-2026-65414, an out-of-bounds write vulnerability in the same operating systems addressed with improved bounds checking. These updates are crucial for all Apple device users, as the vulnerabilities could allow apps to modify protected data or lead to code execution. Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices and Apple Updates Everything, (Mon, Sep 14th).
Several critical vulnerabilities have been disclosed in IBM products, including Langflow OSS, ContextForge MCP Gateway, and DataStage. CVE-2026-81204 and CVE-2026-85025 highlight critical code execution and arbitrary code access risks in IBM Langflow OSS due to code injection and improper security enforcement, respectively. Additionally, CVE-2026-78573 points to an administrative access vulnerability in IBM ContextForge MCP Gateway stemming from default credentials. These issues, affecting versions up to 1.11.5 for Langflow OSS and 1.0.7 for ContextForge MCP Gateway, demand prompt attention from organizations utilizing these IBM products. IBM: 25 Vulnerabilities Across Db2, Langflow OSS, and DataStage Disclosed Together and IBM Langflow OSS: Batch of 18 Vulnerabilities Disclosed, Including Critical Code Execution Flaws.
Microsoft's September Patch Tuesday addresses a significant number of vulnerabilities, including critical flaws in Windows. CVE-2026-68839, a heap-based buffer overflow in the Windows USB Mass Storage Class Driver, allows unauthorized attackers to execute code remotely over a network. Another critical vulnerability, CVE-2026-83941, involves missing authorization in Entra ID, enabling authorized attackers to elevate privileges across a network. These vulnerabilities underscore the importance of applying Microsoft's latest security updates to protect Windows systems from remote code execution and privilege escalation attacks. Massive Microsoft Patch Tuesday September 2026 – 973 Vulnerabilities Fixed, Including 2 Zero-Days and Rapid7 Blog.
A series of critical vulnerabilities have been identified in various D-Link and Totolink network devices, primarily involving buffer overflow issues. CVE-2026-90693 in D-Link DIR-878 and CVE-2026-90680 in D-Link DIR-823G, along with CVE-2026-90608 and CVE-2026-90606 in Totolink A3002MU, all stem from improper handling of network traffic parameters, allowing for remote code execution. These flaws in the WAN Settings and HNAP1 components, among others, expose a wide range of home and small business routers to potential compromise. Patches or specific mitigation guidance are still pending for these devices.
Critical vulnerabilities have been disclosed in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. CVE-2026-76441 and CVE-2026-20353 are listed as critical, with Cisco's internal security review identifying these issues. While the specific technical details are not fully elaborated in the provided information, the nature of these products suggests potential impacts on email security and threat detection capabilities. Organizations using these Cisco products should monitor for forthcoming security advisories and updates from the vendor.