D-Link Routers, VeloCloud, and Veeam Under Active Attack

by The Creator | Sep 22, 2026

Six critical vulnerabilities are under active attack right now, affecting D-Link routers, VeloCloud SD-WAN, Veeam backup software, Microsoft SharePoint, WordPress, and 30,000 devices in the WaterPlum campaign. Small business owners must patch or replace affected systems today to avoid breach, downtime, and credential theft.

Today's cybersecurity update for September 22nd, 2026 covers six critical security issues that small business owners need to address immediately.

D-Link has warned customers of a maximum-severity vulnerability affecting legacy DIR-822A dual-band Wi-Fi routers. With a severity score of 10 out of 10 and public proof-of-concept exploit code available, businesses using these end-of-life routers should replace them immediately as no patch will be released.

Attackers are actively exploiting a new flaw (CVE-2026-93952) in on-premises VeloCloud Orchestrator, the server that manages Edge devices in VeloCloud SD-WAN deployments. The flaw allows remote attackers with no login access to compromise systems configured with certificate-based authentication. Organizations using VeloCloud should apply patches immediately.

A critical privilege escalation vulnerability (CVE-2026-32996) in Veeam Agent for Microsoft Windows is being exploited. Public proof-of-concept code released on September 14th allows low-privileged local users to execute commands with NT AUTHORITY\SYSTEM permissions. Organizations using Veeam for backup on shared Windows systems must update immediately.

Microsoft has confirmed a high-severity remote code execution vulnerability (CVE-2026-65660) in SharePoint Server with a CVSS score of 8.8. The flaw affects SharePoint Server 2016, 2019, and Subscription Edition, allowing authenticated, low-privileged attackers to run arbitrary code over a network. Administrators should apply the latest patches.

North Korean attackers compromised 30,000 devices worldwide through the WaterPlum campaign, stealing funds and credentials from 7,000 cryptocurrency wallets totaling $10.7 million. This demonstrates the importance of multi-factor authentication, software updates, and network monitoring.

WordPress has patched a vulnerability called Click2Shell that allows attackers to automatically install and preview themes, potentially leading to remote code execution. Website owners should update WordPress immediately.

Which active attack vulnerabilities threaten your business most?

The immediate threats vary by your tech stack. D-Link DIR-822A routers (CVSS 10.0) will never receive a patch, so replacement is mandatory if you own legacy units. VeloCloud Orchestrator (CVE-2026-93952) and Veeam Agent for Windows (CVE-2026-32996) both have public exploits circulating. Microsoft SharePoint (CVE-2026-65660, CVSS 8.8) requires patching across 2016, 2019, and Subscription Edition. WordPress sites need the Click2Shell patch applied immediately. The WaterPlum campaign demonstrates attackers are also targeting unpatched Windows machines directly to steal credentials and access cryptocurrency wallets. Action: Inventory which systems you use, check CISA advisories for patch availability, and schedule updates within 24-48 hours.

Key takeaways

  • D-Link DIR-822A routers have no patch coming; replace them immediately or accept active breach risk.
  • VeloCloud, Veeam, and SharePoint patches exist now; deploy them before weekend if exploitation is already happening.
  • WordPress and Windows machines in the WaterPlum campaign also under attack; enforce multi-factor authentication across all systems.
  • Document which systems you patched and when; this evidence protects you during breach response and compliance audits.

Frequently asked questions

Do I have time to schedule patches, or must I patch immediately?

Public exploit code exists for D-Link, VeloCloud, and Veeam. Attackers are already exploiting these flaws. Patch within 24 hours if the tool is critical to your business, and replace D-Link routers first since no fix exists.

What if my business doesn't use VeloCloud or Veeam?

Check your stack against all six vulnerabilities: D-Link routers, SharePoint, WordPress, and Windows machines. Even one unpatched system can provide entry to attackers in the WaterPlum campaign. Use CISA alerts to cross-reference your vendors.

How do I know if we're already compromised?

Look for unauthorized VeloCloud or Veeam activity, failed SharePoint login attempts, and new admin accounts you didn't create. If you use cloud backups, verify no unauthorized restore jobs ran. Check network logs for unusual outbound traffic to crypto exchanges.

What's the cost of not patching?

A single breach from any of these flaws can cost $10K-$100K in downtime, recovery, and incident response, plus regulatory fines if customer data is stolen. Patching takes 2-4 hours and costs nothing.

Sources

Keep reading