Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal.
RESPONSECheck Point Patches Actively Exploited Management Server Path TraversalNEW YORKNoah ParkRESPONSECheck Point Patches Actively Exploited Management Server Path TraversalNEW YORKNoah Park
NEW YORK - F5 Networks has confirmed a critical heap-based buffer overflow in BIG-IP Access Policy Manager is under active exploitation, and CISA added it to the Known Exploited Vulnerabilities catalog.
WASHINGTON - The Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalog so that CVE-2026-63077, a critical JetBrains TeamCity On-Premises flaw, is now marked with known ransomware campaign use. Trade press reported the KEV change on Wednesday, September 23, 2026. CISA first added the vulnerability to the catalog on August 5, 2026, after evidence of active exploitation. The live KEV feed lists knownRansomwareCampaignUse as Known for this CVE.
Patchstack and other defenders report pearcmd-based file writes against unpatched WordPress after CVE-2026-87902 disclosure, turning a template-resolution path traversal into a SOC containment problem.