What Are the Latest CERT-In Cybersecurity Alerts for MikroTik, Check Point and Adobe Users?

India’s cybersecurity agency, CERT-In, issued three Critical vulnerability notes on September 16, 2026, covering MikroTik RouterOS, Check Point VPN products and a wide range of Adobe software. The warnings are not routine update reminders. They include authentication bypass, unauthenticated remote-code execution, privilege escalation, data exposure and denial-of-service risks. The three notices appear together on CERT-In’s latest vulnerability-note list.

The Adobe warning is especially urgent because one Commerce flaw, CVE-2026-75650, is already being exploited in the wild. Router owners, network administrators, businesses running VPN gateways and Adobe users should check versions now rather than wait for the next scheduled maintenance window.

CERT-In published the three notes together during a busy September patch cycle. The same September 16 list also carried fresh GitLab and MongoDB warnings, giving enterprise security teams several urgent products to review at once.

Why MikroTik RouterOS Users Need to Patch Quickly

CERT-In’s MikroTik vulnerability note CIVN-2026-0460 covers RouterOS releases before 7.24.2, before 7.23.4 in the 7.x branch, and before 6.49.21 in the 6.x branch. Three vulnerabilities sit behind the warning.

CVE-2026-67277 affects the bandwidth-test service and can expose uninitialised kernel memory or crash a router. CVE-2026-86060 targets the SSH login path and may let an attacker raise privileges. CVE-2026-67276 involves incomplete RSA public-key verification and can lead to authentication bypass and possible administrative control.

MikroTik says fixes are included in RouterOS 7.24.2, 7.23.4, 6.49.21, and 7.25 beta 3. Its September 2026 security notice also tells administrators not to expose SSH to untrusted networks. After updating, users should review logs for unfamiliar accounts, scripts, and configuration changes. RouterOS may mark a compromised device as “Flagged” in its log.

Why Check Point VPN Administrators Face Remote-Code Risk

CERT-In’s CIVN-2026-0459 Check Point warning covers Security Gateway, Security Management Server and Spark Firewall products. Supported versions listed include R81.20, R82, R82.10, R81.10.x and R82.00.x, while R82.20 is listed as unaffected.

The two tracked flaws are CVE-2026-85102 and CVE-2026-85103. Both can be attacked remotely without authentication during VPN certificate processing. The first involves improper certificate validation. The second is a heap-based buffer overflow in ASN.1 certificate decoding. Each carries a CVSS score of 9.8 in published vulnerability records.

That raises the risk for internet-facing VPN infrastructure, where a successful attack could lead to arbitrary code execution, system compromise, access to confidential data or disruption. CERT-In directs administrators to Check Point’s SK1000117 security advisory and SK1000118 security advisory for updates and mitigations.

Why Adobe Users Have an Extra Reason to Act

Adobe’s September 16 CERT-In note CIVN-2026-0458 is unusually broad. It covers products including Experience Manager, ColdFusion, Photoshop, Illustrator, Animate, Photoshop Mobile, Adobe Commerce, Magento Open Source, Acrobat, Acrobat Reader and Campaign Classic.

The vulnerabilities range from code injection and SQL injection to path traversal, memory errors, access-control failures and operating-system command injection. A malicious file, request or crafted input can be enough for exploitation in some products.

The sharpest warning concerns CVE-2026-75650 in Adobe Commerce, Commerce B2B and Magento Open Source. Adobe’s APSB26-146 security bulletin gives it a CVSS score of 10.0, says authentication is not required, and confirms exploitation in the wild. Adobe has released a dedicated hotfix and tells affected Commerce and Magento users to install it.

Creative users should not ignore the wider batch. Photoshop 2026 version 27.6 and earlier, Illustrator 2026 version 30.7 and earlier, and Acrobat Reader Continuous 26.002.21900 and earlier are among the versions named by CERT-In.

What Should Users Do After the CERT-In Alerts?

The common thread is simple: identify the exact product version, use the vendor’s official patch path and reduce exposed services until updates are complete.

  • MikroTik users should update RouterOS, restrict SSH and inspect logs or configuration for suspicious changes.
  • Check Point administrators should apply the relevant hotfixes or mitigations and review exposed VPN gateways first.
  • Adobe users should update affected applications through official channels and prioritise the Commerce CVE-2026-75650 hotfix.
  • Businesses should record which devices and applications were patched, then monitor them for unexpected activity.

CERT-In’s vulnerability-note list remains the best government page for checking whether newer alerts have appeared after September 16. Users should avoid patch links arriving through unsolicited email or chat and instead open CERT-In or the vendor’s security page directly.

FAQs

Are the latest MikroTik, Check Point and Adobe CERT-In alerts all Critical?
Yes, CERT-In rated all three September 16 vulnerability notes Critical for affected products and deployments.

Which Adobe flaw is already being exploited?
CVE-2026-75650 affects Adobe Commerce and Magento, allowing unauthenticated remote code execution on vulnerable servers today.

Is Check Point R82.20 affected by the latest VPN warning?
No. R82.20 is specifically listed as unaffected by the two newly reported VPN vulnerabilities today.

Which MikroTik versions contain the September security fixes?
MikroTik lists patched releases as 7.24.2, 7.23.4, 6.49.21, plus 7.25 beta 3 for affected devices.

Where should users download security updates from?
Download updates only from CERT-In-linked official vendor pages, not unsolicited emails, messages or pop-ups online.

Stay Ahead of India’s Latest Tech & Cyber Updates

Did TCS And HCLTech Face Breach Claims?
Check out the latest dark-web claims and what data was allegedly exposed.

Could Bank Of Baroda Data Be Exposed?
Find out what customers should check after the reported breach claim.

Why Are Tech Layoffs Rising In 2026?
Uncover the latest layoff trends and why India has been heavily affected.

Which Products Did CERT-In Flag Today?
Browse the cybersecurity vulnerabilities affecting GitLab, MongoDB, Adobe, MikroTik, and Check Point.

Could UPI Payments Above ₹2,000 Cost?
Dive into the latest policy debate around potential UPI merchant payment fees.

Related Articles