This week's useful work is three concrete jobs: refresh ScreenConnect clients after CISA listed a file-transfer bug as exploited, confirm Check Point VPN gateways have this week's LivePatch or Jumbo take, and patch MikroTik RouterOS if SSH or Winbox is reachable from anywhere you do not fully trust.
None of these items means every office is already compromised. Each one only applies if you actually run that product. A UniFi gateway, FortiGate, or Microsoft 365 tenant is not ScreenConnect, Check Point, or RouterOS.

ScreenConnect clients need 26.6.5, not only a patched server
What happened
ConnectWise published a ScreenConnect 26.6.5 security patch on September 8, 2026. The bulletin describes a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ConnectWise states that ScreenConnect servers are not impacted.
CVE-2026-84869 is listed as missing authorization (CWE-862) and improper privilege management (CWE-269), CVSS 9.9. ConnectWise rates severity Important and priority 1 High: vulnerabilities that are either being targeted or have higher risk of being targeted by exploits in the wild. Affected versions are ScreenConnect prior to 26.6.5.
CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog on September 11, 2026, based on evidence of active exploitation. Catalog wording: ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation. CISA marks ransomware use as unknown. The federal due date in that catalog row is September 14, 2026, a BOD 26-04 deadline for federal civilian agencies, not a patch deadline for private businesses. CISA still encourages every organization to treat KEV items as a priority queue.
Who is affected
Any office that uses ConnectWise ScreenConnect for remote support or unattended access, cloud or on-premises, if host clients or access agents are still below 26.6.5.
ConnectWise's cloud note says no action is required on the hosted server, because those servers were updated. The same bulletin still tells you to reinstall host clients and update access agents after the server-side change. On-premises partners still have to upgrade the installation to 26.6.5, then do the same client refresh. Automate-integrated on-prem ScreenConnect is updated through Automate Product Updates if Automate Assurance is active.
A different remote tool (Splashtop, TeamViewer, Quick Assist, or an RMM agent that is not ScreenConnect) is not this CVE. A firm with no ScreenConnect can skip this item.
What to check or fix now
- Confirm whether staff or your MSP uses ScreenConnect (sometimes branded as ConnectWise Remote Access), including leftover unattended agents.
- Cloud: treat the server as already patched, then reinstall host clients and update access agents so endpoints leave the old client build.
- On-premises: upgrade to ScreenConnect 26.6.5 or later, then reinstall host clients and update access agents. A license out of maintenance cannot take the current release until it is renewed.
- If you cannot patch yet, ConnectWise's temporary mitigation is to edit Administration, Security, Roles and deselect the TransferFiles permission on each session group. That is not a substitute for 26.6.5.
- If a ScreenConnect session was used against an unpatched client after CISA listed exploitation, treat that endpoint as an incident lead: unexpected files, new services, and odd outbound connections.
How to prevent it
Remote-support clients are software on every helped PC. Put ScreenConnect version checks on the same list as Windows, and do not leave unused access agents installed after a vendor or contractor finishes. Related reading: the importance of regular software updates.
Check Point VPN needs this week's LivePatch or Jumbo take
What happened
Check Point published two Critical VPN certificate bugs on September 9, 2026:
- CVE-2026-85102: improper validation of certificate data during VPN negotiation may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway. CVSS 9.8. Affected products: Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN. R82.20 is not affected.
- CVE-2026-85103: a heap overflow in the VPN certificate ASN.1 decoding flow may allow a remote attacker to execute arbitrary code on the management and Security Gateway. CVSS 9.8. Affected products: Security Management Server, Security Gateway, and Check Point Spark Firewall. R82.20 is not affected.
Both advisories list the same version families: R81.20, R82, R82.10; end-of-support R80 through R80.40, R81, and R81.10; plus R81.10.x and R82.00.x.
Fixes Check Point documents:
- LivePatch Take 24 for R82.10, R82, and R81.20 (automatic if LivePatch auto-install is on)
- Jumbo Hotfix Accumulator: R82.10 Take 44 or later, R82 Take 126 or later, R81.20 Take 166 or later
- Spark: R82.00.10 starting from Build 2325, R81.10.17 starting from Build 4968
Site-to-site workaround, until you patch: disable implied rules for VPN and manually define VPN access for UDP/500 and UDP/4500 to specific peer IP addresses. Check Point says that workaround does not apply to locally managed Spark Firewall.
The Dutch NCSC alert dated September 10, 2026 rates the chance of abuse and possible damage as high and expects attempts soon. It also says no public proof-of-concept has been reported. These CVEs were not in CISA's KEV catalog snapshot from September 11, 2026. Do not treat them as already listed as exploited by CISA.
Who is affected
Offices that run Check Point Security Gateway, Security Management Server, or Spark Firewall with site-to-site or remote-access VPN on a build in Check Point's affected list. A FortiGate, SonicWall, UniFi gateway, or Microsoft Always On VPN is a different product. A firm with no Check Point OS can skip this item.
What to check or fix now
- Inventory: is there a Check Point gateway, management server, or Spark box, including a leftover appliance in a closet.
- If LivePatch auto-install is enabled on R81.20, R82, or R82.10, confirm Take 24 with
cpinfo -y CPupdatesandcplp listin Expert mode. Check Point's expectedcplp listoutput names both CVE-2026-85102 and CVE-2026-85103. - If LivePatch is not in play, move to the Jumbo takes or Spark builds listed above.
- For site-to-site VPN, until the fix is on, restrict UDP/500 and UDP/4500 to known peer addresses as Check Point describes. Do not use that as the long-term plan on Spark local management.
- End-of-support R80/R81 trains are in the affected list. If you are still on those, this week's hotfix is not a substitute for leaving an unsupported VPN gateway on the internet.
How to prevent it
Internet-facing VPN concentrators need a named owner, a current Jumbo or LivePatch habit, and management off the public internet. Related reading: why your business needs a strong firewall.
MikroTik RouterOS needs 6.49.21, 7.23.4, or 7.24.2 if SSH is exposed
What happened
MikroTik's September 3, 2026 security note says it found a security vulnerability in RouterOS, published fixes on all channels, and called it an important security update. MikroTik wrote that most configurations are not at risk, but upgrading is highly recommended. Fixed trains: 7.25 beta 3, 7.24.2, 7.23.4, and 6.49.21. MikroTik also says: make sure SSH is not open to any untrusted networks; default configuration blocks that port from the internet, but if you opened it, restrict it or use a VPN such as WireGuard and do not open management ports at all. After upgrading, inspect for unknown scripts, users, or other config you do not recognize, even if the device is not in Flagged state.
CERT Polska, dated September 5, 2026, says it identified six RouterOS vulnerabilities. Combining two of them allows an attacker to take full control of the device without authentication if the device supports remote access using SSH. CERT named that chain MikroTrick. CERT says it has confirmation that attackers are exploiting that combination against devices whose SSH service is accessible from public networks, and that the released patches prevent the observed attacks.
The three CERT highlights:
- CVE-2026-67276: SSH authentication bypass (CVSS 9.2). RouterOS did not compare the entire RSA public key.
- CVE-2026-86060: SSH session privilege manipulation via a crafted username (CVSS 9.2). A crafted username could yield a session with full administrative privileges.
- CVE-2026-67277: bandwidth-test memory disclosure and crash (CVSS 8.8). An unauthenticated connection could reach a state that should require login, leaking kernel memory or restarting the system.
CISA added CVE-2026-67277 and CVE-2026-86060 to KEV on September 10, 2026, based on evidence of active exploitation. Ransomware use is unknown for both. The federal due date in those rows is September 13, 2026. CVE-2026-67276 is part of CERT's MikroTrick write-up but was not in CISA's two-CVE alert. Patch the same RouterOS trains anyway.
CERT's observed-attack notes: successful attacks including creation of a highly privileged user named "ops" originated from 82.192.72.4 since at least 2 September; 103.102.31.18 was used in exploit attempts. Absence of those traces does not rule out unauthorized activity. MikroTik's Flagged marker detects only selected traces; absence of Flagged is not proof the device is safe.
Who is affected
Offices that run MikroTik RouterOS (hardware or CHR) below 6.49.21, 7.23.4, or 7.24.2, especially if SSH, WWW/WWW-SSL, or the bandwidth-test server is reachable from the internet. A consumer ISP router, a UniFi Dream Machine, or a FortiGate is not RouterOS. A firm with no MikroTik can skip this item.
What to check or fix now
- Inventory MikroTik devices, including a leftover hEX or CHR used as a VPN endpoint.
- Upgrade to 6.49.21, 7.23.4, or 7.24.2 (or 7.25 beta 3 if you already run the development channel). MikroTik says Check for updates should already offer it.
- Close SSH, Winbox, WWW, and bandwidth-test from the public internet. Prefer WireGuard or another VPN for admin, which is MikroTik's own guidance.
- After the upgrade, check
/system/device-mode/printfor Flagged, then look for unknown users (CERT names "ops"), scripts, scheduler tasks, proxy servers, and tunnels. - If Flagged, logs, or config suggest compromise: isolate the device, save logs and config, factory-reset, rebuild from a known-good plan, and rotate passwords and keys. CERT says do not blindly restore a full backup from a possibly compromised device.
How to prevent it
Treat a MikroTik as an internet server if any management service is on a public address. Default-deny SSH from WAN is not optional once someone has opened it for "just a minute." Related reading: why your business needs a strong firewall.

What to do this week
- Find ScreenConnect host clients and access agents. Move them to 26.6.5 (cloud: refresh clients even if the hosted server is already patched).
- If you cannot take 26.6.5 today, remove TransferFiles from ScreenConnect roles until you can.
- On any Check Point gateway or Spark firewall, confirm LivePatch Take 24 or the Jumbo/Spark builds Check Point listed for CVE-2026-85102 and CVE-2026-85103.
- Upgrade MikroTik RouterOS to 6.49.21, 7.23.4, or 7.24.2, and take SSH off the public internet.
- If a MikroTik was internet-SSH-exposed and unpatched after early September, look for Flagged, an "ops" user, and the ssh:-2 log lines before you call the box clean.
If you need someone who can handle these checks for you, reach out to us. We would be happy to help.
Sources
- CISA, September 11, 2026: three known exploited vulnerabilities added to the catalog
- CISA, September 10, 2026: two known exploited vulnerabilities added to the catalog
- CISA Known Exploited Vulnerabilities catalog (JSON)
- ConnectWise ScreenConnect 26.6.5 security bulletin, September 8, 2026
- Check Point sk1000117 (CVE-2026-85102)
- Check Point sk1000118 (CVE-2026-85103)
- NCSC-NL, September 10, 2026: Check Point VPN alert
- CERT Polska, September 5, 2026: MikroTik RouterOS MikroTrick
- MikroTik, September 3, 2026: September 2026 vulnerability
Powerful IT Systems · Sussex, WI
Master's degree in Computer Science with 15+ years of hands-on IT experience serving Milwaukee-area businesses.
