Check Point Zero-Day, WordPress Critical Flaw, and What Your MSP Should Be Telling You This Week
Two vulnerabilities confirmed actively exploited in the last 24 hours. One is in the firewall management infrastructure that many UK businesses rely on through their managed service providers. The other is in WordPress, the platform running an estimated 43% of all websites on the internet.
Neither is hypothetical. Both have documented exploitation. Both have patches or mitigations available. The question is whether your provider has acted.
Story One: Check Point’s Management Server Is Being Exploited Right Now
CISA added CVE-2026-93616 to its Known Exploited Vulnerabilities catalogue on 22 September 2026. That designation matters: it means exploitation in the wild has been confirmed, not theorised.
The flaw affects Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. The mechanism is a path traversal vulnerability. An unauthenticated attacker can use it to upload and execute arbitrary scripts directly on the affected system.
Translation for a non-technical audience: someone with no credentials, no account, and no prior access can send a specially crafted request to your firewall’s management server and run code on it. Check Point confirmed targeted attacks exploiting this flaw occurred in July.
A second Check Point vulnerability, CVE-2026-85102, was added to the KEV list on the same day. This one affects Check Point Security Gateway and Spark Firewall products using Site-to-Site VPN or Remote Access VPN. It allows unauthenticated remote code execution via improper certificate validation.
That is two confirmed actively exploited flaws in Check Point infrastructure, disclosed on the same day.
Why this matters to UK small businesses specifically. Check Point products are widely deployed in managed security environments. Many UK SMBs do not run these products directly: their MSP manages the firewall on their behalf. That relationship means the patching responsibility sits with the provider. It also means you may have no visibility into whether the fix has been applied.
If your MSP manages a Check Point firewall for your business, the appropriate response is a direct question: have you patched CVE-2026-93616 and CVE-2026-85102, and when was this done?
If the answer is vague, that is information.
Story Two: WordPress Core Has a Critical Unauthenticated Flaw
WordPress issued a patch for CVE-2026-87902 on 22 September 2026. The flaw is a path traversal vulnerability in WordPress core, meaning the base software itself, not a third-party plugin.
An unauthenticated attacker can exploit the flaw to make a WordPress site load a PHP file from outside its intended theme directories. On certain server configurations, that capability extends to remote code execution: the attacker can run arbitrary code on the web server.
WordPress is the most widely used content management system on the internet. It powers a substantial proportion of UK small business websites, charity sites, and local government pages. The attack surface is significant.
The distinction worth noting: this is a core vulnerability, not a plugin issue. The usual advice to keep plugins updated is correct but insufficient here. The WordPress core installation itself requires updating.
The practical gap. Many small business websites are managed by web developers or agencies under loose maintenance arrangements. Some are effectively unmanaged. If your business website runs WordPress and you are not certain it has been updated in the past 48 hours, that is a gap worth closing today.
The version check is straightforward. Log in to your WordPress admin dashboard. The version number is displayed in the bottom right corner. If it does not reflect the latest release, the site is vulnerable.
The Pattern Behind This Week’s Disclosures
Looking at the full picture of what CISA confirmed on 22 September, the Check Point and WordPress flaws are the two items with the most direct relevance to UK small businesses. But the broader pattern is worth noting.
Arista’s VeloCloud Orchestrator (CVE-2026-93952) was also added to the KEV list on the same day. VeloCloud is SD-WAN infrastructure, the kind of networking technology increasingly used by businesses with multiple sites or hybrid working setups. That exploitation is confirmed and active.
The common thread across all three confirmed exploits: they are being used against infrastructure that businesses often assume is someone else’s responsibility to maintain. The firewall is the MSP’s job. The website is the web developer’s job. The network infrastructure is the connectivity provider’s job.
That assumption is understandable. It is also the gap that attackers are walking through.
Supply chain accountability is not bureaucratic language. When your security depends on a third party’s patching discipline, you have a practical interest in knowing whether that discipline exists. The question is not whether you trust your MSP. The question is whether trust is a sufficient substitute for verification.
How to Use This as a Competitive Differentiator
If your business is in professional services, financial services, or any sector where clients entrust you with sensitive data, your security posture is a commercial variable. Increasingly, procurement processes include security questionnaires. Enterprise clients ask about patch management.
Being able to say that your organisation actively monitors vulnerability disclosures, asks suppliers accountability questions, and can demonstrate a patch management process is a concrete differentiator. It does not require a large budget. It requires a consistent process and the willingness to ask awkward questions of providers.
The businesses that cannot answer those procurement questions lose contracts. The ones that can answer them, and can evidence the answers, win them.
Making the Business Case
Three arguments for getting budget and board attention on this:
First, the cost of inaction is quantifiable. A compromised website leads to ICO notification obligations under UK GDPR, potential fines, reputational damage, and the cost of remediation. A compromised firewall potentially exposes your entire internal network. Neither scenario is cheap.
Second, the regulatory environment is tightening. The ICO’s enforcement posture on data breaches has shifted. Organisations that cannot demonstrate reasonable security measures face harder questions than those that can. Patching known exploited vulnerabilities promptly is a baseline that regulators expect.
Third, supply chain risk is now a board-level question. The NCSC has been explicit on this. If your security depends on your MSP’s patching discipline, and you have no mechanism to verify that discipline, you have a governance gap. Boards are increasingly being asked about this by auditors and insurers.
What to Do Before the End of This Week
-
Contact your MSP today if they manage a Check Point firewall. Ask specifically whether CVE-2026-93616 and CVE-2026-85102 have been patched, and request confirmation in writing. A competent provider will have this information readily available. One that cannot answer promptly is telling you something.
-
Check your WordPress version now. Log in to your WordPress admin panel. Look for the version number displayed at the bottom of the dashboard. If your site is not on the latest release, update it immediately or instruct whoever manages your site to do so and confirm when it is done.
-
Ask your MSP what their standard response time is for CISA KEV items. Known exploited vulnerabilities are the highest priority category. There is no defensible argument for slow response on these. If your provider does not have a documented process for KEV items, that is a gap in your service agreement.
-
Audit your third-party dependencies. Make a list of the technology infrastructure your business depends on that is managed by someone else: firewalls, websites, cloud services, network equipment. For each one, ask: do I know who is responsible for patching it, and how would I know if they had not?
-
Review your cyber insurance terms. Many policies require that known critical vulnerabilities are patched within a defined window. If you are relying on insurance as a backstop and your infrastructure has unpatched KEV items, you may find coverage disputed after an incident.
Before you go: follow the show wherever you listen, and leave a rating or review if you found this useful. Drop a comment with your thoughts, particularly if you have had the conversation with your MSP about Check Point patching and want to share how it went. And share this episode with someone running a small business who thinks this week’s news does not apply to them. It probably does.