Free delivery

GGuestNot signed in
You're not signed in
LoginCreate account

TYO Store Blog

Blog

Guides, product insights and announcements from the TYO Store team.

Security

WatchGuard SAML Flaw: Logged In to the Portal, Let In to the VPN

10/7/2026

WatchGuard has patched CVE-2026-86101, an authorisation bypass in Fireware's SAML login that let a user who was only allowed the Access Portal open a Mobile VPN with SSL session instead. Fixed in Fireware 12.12.3, 2026.2.3, 2026.3.2 and 12.5.21; not exploited.

#Security #Networking #WatchGuard #Small Business

Security

MikroTik Web Flaw: The 9.8 Fix Shipped Six Weeks Before the Warning

10/7/2026

CVE-2026-84411 lets an unauthenticated attacker run code as root on a MikroTik router through its web interface with a single request. The fix went out in RouterOS 7.24 on 14 August with no announcement; CISA disclosed it on 29 September and MikroTik still has not. Here is what to check and what to close.

#Security #Networking #MikroTik #Small Business

Security

WatchGuard Firebox Flaw: A DHCP Packet Can Hijack Your Firewall

10/2/2026

WatchGuard has patched CVE-2026-81433, a stack buffer overflow in the Firebox's DHCP fingerprinting daemon that lets anyone on your internal network run code on the firewall with no password. Fixed in Fireware 12.12.3, 2026.2.3 and 2026.3.2; not exploited yet.

#Security #Networking #WatchGuard #Small Business

Security

FortiMail Zero-Day: The Encryption Feature Is the Way In

10/2/2026

Fortinet has confirmed a CVSS 9.8 flaw in FortiMail's Identity-Based Encryption portal is being exploited in the wild, letting attackers write files to the appliance with no login. Fixed builds were still listed as upcoming when the advisory landed, so the workaround is the fix for now.

#Security #Networking #Fortinet #Small Business

Security

Check Point Zero-Day Hit the Server That Manages the Firewall

9/22/2026

Check Point has confirmed a CVSS 9.8 path traversal flaw in its Security Management Server was exploited in July, two months before a fix existed, and a second VPN flaw patched on 9 September is now being attacked too. Both are on CISA's exploited list.

#Security #Networking #Check Point #Small Business

Security

Cisco ISE Zero-Day: The Gatekeeper Was Bypassed Before the Patch

9/22/2026

A maximum-severity, unauthenticated authentication bypass in Cisco Identity Services Engine (CVE-2026-76460) was already being exploited when Cisco disclosed it — found only because a customer's network had been compromised. Here's what happened and what to check.

#Security #Networking #Cisco #Small Business

Security

Cisco Fixes a Root Flaw in Its Firewall Management Center

9/22/2026

Cisco has patched five flaws in Secure Firewall Management Center, including a CVSS 9.1 bug that lets an already-authenticated attacker reach root over the management channel — the latest in a year where FMC itself has become the target.

#Security #Networking #Cisco #Small Business

Security

Synology Fixes Two Critical NAS Flaws No Login Could Stop

9/18/2026

Synology's SA-26:13 patches eight DSM vulnerabilities, including two unauthenticated CVSS 9.8 bugs that let remote attackers read or write arbitrary files on a NAS with no credentials at all. Here's what's confirmed, and what to do about it.

#Security #Networking #Synology #Small Business

Security

Check Point VPN Flaws: Two 9.8s, and a Fix That Installs Itself

9/11/2026

Check Point has disclosed two CVSS 9.8 flaws in how its Quantum Security Gateways and Quantum Spark firewalls handle VPN certificates, exploitable with no login. Fixes shipped the same day, and for many customers they installed automatically. Whether yours did depends on one setting.

#Security #Networking #Check Point #Small Business

Security

TP-Link Archer Flaw: Root Access From Inside Your Own Wi-Fi

9/8/2026

An unauthenticated command-injection flaw in the parental-control feature of TP-Link's Archer BE800, BE3600 and AX75 lets anyone on the local network take root on the router. Fixes are out; here's why "LAN-only" isn't the comfort it sounds like.

#Security #Networking #TP-Link #Small Business

Contact Us

Email: [email protected]

Phone: 1300 989 334

About

Your one-stop technology hub for all your networking, security, and IT needs. From cutting-edge networking solutions to robust security products, we provide everything your business requires to stay connected, secure, and efficient. Whether you're looking for advanced hardware, software, or services, we offer reliable, innovative technology tailored to help you build and protect your digital infrastructure.

Copyright © 2026 TYONLINE TECHNOLOGY PTY. LTD. All Rights Reserved.