Skip to content
Beveiligingsnieuws

Security Week 31, 2026: Critical Patches Checklist

beveiligingswaarschuwingen week 31

Welcome to security week 31 (2026). This overview highlights the most urgent security warnings from the week and turns them into a practical, action-focused checklist. The common theme is straightforward: exploitable vulnerabilities are being discovered and, in several cases, actively abused—so speed matters.

Below, you’ll find the topics grouped by urgency and impact. Each section includes a direct link to the original advisory for details, plus clear next steps you can take right away.

Critical: Patch these systems first

If you have to triage quickly, start with fixes that enable account takeover, remote code execution, authentication bypass, or direct network compromise. The items below are all labeled critical and are the highest priority for security week 31.

VMware infrastructure (vCenter, ESX, Workstation, Fusion)

Multiple critical VMware issues have been addressed, affecting commonly used components such as vCenter and ESX, plus VMware desktop products. Because these platforms sit at the center of virtualization workflows, delayed patching can have cascading impact across workloads.

Action: review your VMware footprint and apply the vendor fixes immediately. If you can’t patch right away, at least restrict management access, monitor logs, and validate that exposure is minimized until updates are in place.

Read: Kritieke VMware-kwetsbaarheden verholpen

TeamCity: critical unauthenticated code execution

A critical code execution vulnerability in TeamCity has been patched. The key detail is that the issue allows unauthenticated attackers to execute code, which elevates the risk of fast exploitation.

Action: update TeamCity promptly using the patched releases. Then verify that the build server is running the intended version and that any external access paths are reviewed (for example, whether the service is reachable from the internet).

Read: TeamCity kritiek code-executie lek (patch)

FortiClient EMS: actively exploited critical flaw

FortiClient EMS has a critical vulnerability (CVE-2026-35616) that is described as being actively abused. When exploitation is already happening, you should treat patching as urgent incident response rather than a routine update cycle.

Action: apply the FortiClient EMS security update without delay, and follow up with monitoring checks to confirm normal behavior. If your environment supports it, validate that endpoint management integrity is intact and that no unauthorized changes have occurred.

Read: FortiClient EMS kwetsbaarheid (CVE-2026-35616)

cPanel and WHM: CVE-2026-41940, patch quickly

CVE-2026-41940 in cPanel and WHM is described as very serious (critical severity). Since cPanel/WHM commonly handles web hosting administration, successful exploitation can lead to severe outcomes, including unauthorized access and potential privilege escalation.

Action: install the cPanel updates quickly, following the recommended update procedure. After patching, review admin-related logs and verify that expected accounts and permissions remain unchanged.

Read: CVE-2026-41940 in cPanel en WHM

PAN-OS / GlobalProtect: active exploitation—update now

There is active misuse of PAN-OS involving a very severe vulnerability in GlobalProtect, which can enable unauthorized access. VPN and remote access gateways are high-value targets because they provide pathways into internal networks.

Action: install the PAN-OS updates immediately and check for indicators of compromise (IoCs) as advised. If you use GlobalProtect for remote access, consider temporarily tightening access policies during the validation window after updating.

Read: Actief misbruik PAN-OS: update nu nodig

Microsoft Office vulnerabilities: update Office and SharePoint

Office-related vulnerabilities can affect users through documents and collaboration workflows. The risk depends on exposure, but because Office is widely used, you should treat this as a high-impact maintenance task during security week 31.

Action: install updates for Word, Excel, PowerPoint and ensure that SharePoint components are addressed per your environment. After patching, remind users to avoid opening suspicious files and keep macro and download controls aligned with your security policy.

Read: Installeer updates Microsoft Office-kwetsbaarheden

WordPress core: critical issues, and signs of abuse

Critical vulnerabilities in WordPress core have been fixed, and the advisory notes that misuse is already being observed. When core software is affected, the risk applies broadly to sites running vulnerable versions.

Action: check your WordPress version, update WordPress core to the patched release, and confirm that plugins and themes remain compatible. Then review recent admin activity, user creation events, and changes to configuration files.

Read: Ernstige kwetsbaarheden WordPress core

Oracle Fusion Middleware: direct critical exposure

Oracle Fusion Middleware has critical vulnerabilities (described with the highest severity). Middleware components often face network traffic and can provide an entry point for attackers if unpatched.

Action: apply Oracle security updates quickly. Validate that the running services reflect the updated packages and confirm that network exposure matches your intended architecture.

Read: Update Oracle Fusion Middleware direct

Check Point SmartConsole: PoC available—apply jumbo hotfixes

A Proof-of-Concept (PoC) for CVE-2026-16232 is shared for Check Point SmartConsole. Even if exploitation is not confirmed everywhere, a public or shared PoC reduces the barrier for attackers.

Action: apply the relevant Jumbo Hotfixes as soon as possible. After updating, verify that SmartConsole components are on the expected versions and monitor for unusual management console behavior.

Read: Rapid7 PoC CVE-2026-16232 in Check Point

Ruflo MCP flaw: unauthenticated RCE and AI memory poisoning

The Ruflo MCP flaw is described as enabling unauthenticated remote code execution via an open MCP bridge. The advisory also highlights the risk of AI memory poisoning, including the theft of API keys, conversations, and AI-related memory.

Action: restrict or remove exposure of any MCP bridge endpoints that are reachable from untrusted networks. Apply the vendor guidance or compensating controls promptly and review access attempts, API usage anomalies, and unexpected changes in AI-related components.

Read: Ruflo MCP-flaw: unauth. RCE & AI memory poisoning

VMware again: vCenter and ESX critical fixes

In addition to the broader VMware coverage, there is a dedicated warning focused on vCenter and ESX. The described issues include authentication bypass and code execution as well as VM escape scenarios—signals that patching should not be postponed.

Action: ensure vCenter and ESX hosts are updated to the fixed releases. Then validate that access controls are working as expected and that management-plane access is limited to trusted networks and identities.

Read: VMware kritieke kwetsbaarheden vCenter en ESX

Cisco FMC zero-day: static credentials abused (KEV listed)

Cisco FMC has a zero-day described as being misused with static credentials and included on the KEV list. Even when the vulnerability isn’t fully understood in your environment, the practical message is clear: attackers can log in and read sensitive data using known credential behavior.

Action: update FMC immediately and, where applicable, rotate relevant credentials after applying the fix. Review authentication logs for unusual login sources, and confirm that access to management interfaces is tightly controlled.

Read: Cisco FMC zero-day: static credentials

High: Still patch fast, then verify exposure

The next group is labeled high. These issues may not be as severe as the critical items, but they are still serious—especially if your systems are reachable from untrusted networks or used in privileged workflows.

Microsoft System Center: CVE-2026-33825 action needed

CVE-2026-33825 in Microsoft System Center is described as a high-risk vulnerability that is being actively exploited. System Center environments often manage large parts of an organization’s IT stack, so compromise can accelerate further attacks.

Action: install the Microsoft updates quickly and verify the patched version in your managed endpoints and servers. Also check for suspicious changes in monitoring, configuration, or deployment activity after patching.

Read: CVE-2026-33825 in Microsoft System Center

Check Point VPN: vulnerabilities actively misused

Serious vulnerabilities in Check Point Remote and Mobile Access VPN are described as being actively abused. This is especially concerning because VPN appliances commonly become a gateway between the internet and internal resources.

Action: update the VPN components as advised and check indicators to reduce the window of exposure. If possible, validate that VPN authentication and session handling are behaving normally, and review access logs for unexpected geographies or user patterns.

Read: Ernstige kwetsbaarheden Check Point VPN

FortiSandbox: risk of insecure VNC exposure

FortiSandbox is flagged for a risk where VNC access might be exposed via a VNC server used by scan virtual machines. If an attacker can connect to VNC endpoints without proper authentication, they may gain visibility or control opportunities depending on configuration.

Action: confirm which FortiSandbox components are affected and apply the recommended fixes/models updates. Also review network access rules so that VNC interfaces are only reachable from trusted systems (not broad network segments).

Read: FortiSandbox onbeveiligde VNC-toegang

How to execute the patch plan today

With so many urgent topics, the fastest route is a structured approach. Use this short workflow to manage security week 31 across teams.

1) Identify what you actually run

Start with an inventory: VMware products, TeamCity, FortiClient EMS, cPanel/WHM, PAN-OS/GlobalProtect, Office/SharePoint deployments, WordPress versions, Oracle Fusion Middleware, Check Point components, and any MCP bridges or related integrations.

If you don’t know your versions, prioritize asset discovery for the items above before scheduling maintenance.

2) Order by exposure and exploitability

As a rule of thumb, public-facing services and remote access components come first (VPNs, management consoles, hosting panels, and edge gateways). Then focus on internal platforms that provide control over many workloads (virtualization management, system management suites).

For each system, confirm whether it’s reachable from untrusted networks and whether it has the characteristics described in the advisory (for example, unauthenticated exposure or active exploitation).

3) Patch, then validate

After applying updates, validate that services start cleanly and that version checks confirm the patched state. Follow up with targeted log review where the advisories mention active misuse or IoCs.

If you lack time for deep investigation, at least check authentication logs, unusual admin activity, and changes to configuration baselines.

4) Reduce the blast radius while patching is in progress

If some systems can’t be patched immediately, temporarily restrict access paths: limit management interfaces to trusted IP ranges, enforce strong authentication, and avoid exposing administrative consoles unnecessarily.

Combine this with monitoring so you can quickly detect anomalies during the transition.

Quick practical advice

For security week 31, don’t treat this list as “to-do someday.” Pick a deadline, patch the critical items first (especially VPN, hosting panels, and virtualization management), and then verify the patched versions and log activity within the same maintenance window where possible.

If you want a single action you can take right now: compile your exposure list for VMware, TeamCity, FortiClient EMS, cPanel/WHM, PAN-OS/GlobalProtect, Check Point components, and any MCP bridge endpoints—then schedule updates in that order.