KING TECHNOLOGYSolutions Group

This is the Market Pulse edition of Sep 25, 2026, kept as it was published. Read the current edition →  ·  All past editions

Market Pulse  ·  edition of Sep 25, 2026 What moved this month in the market and in security, and what it means for you.

The vendor moves, security alerts, licensing changes and funding signals shaping IT and security operations for businesses and public organizations alike, read from the practitioner's side of the table.

Networking

Juniper's partner program folds into HPE's

HPE closed its Juniper acquisition in July 2025. From Nov 1, Juniper partners move to HPE Partner Ready Vantage. What it means: if your firewalls or switches are Juniper, confirm your reseller's standing and support path before your next renewal or E-Rate bid.

Security

CISA flags exploited SharePoint and Mikrotik RouterOS flaws

CISA added two more actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: a code-injection flaw in on-premises Microsoft SharePoint Server that lets a logged-in user run arbitrary code, and an SSH authentication-bypass bug in Mikrotik RouterOS that lets an unauthenticated attacker open a session and alter device files. Federal agencies must remediate by Sep 28. What it means: cities and districts still running SharePoint on premises, or RouterOS-based routers in budget network builds, should patch now and confirm SSH management isn't reachable from untrusted networks. Source: CISA

E-Rate

FCC's E-Rate overhaul review hits its first deadline

The FCC's proceeding reviewing E-Rate's scope, size and even a possible narrowing over screen-time concerns closes for initial comments Sep 26, with reply comments due Nov 12. It's a separate, more consequential policy track than the routine fall filing deadlines. What it means: district and library technology leaders, and the consultants who support them, should read the docket and weigh in by Nov 12; the outcome could reshape which devices and services qualify for E-Rate discounts. Source: Federal Register

ServiceNow · Security

ServiceNow patches two max-severity AI Platform flaws

ServiceNow's Sep 24 advisory fixes five AI Platform vulnerabilities, including an unauthenticated SQL injection and a missing-authorization bug, each rated a maximum CVSS 10.0, plus three more high-severity access-control issues. ServiceNow reports no evidence of exploitation. What it means: if you run ServiceNow for ITSM, HR or procurement, confirm with your admin team or MSP that the patch is applied, especially on any instance reachable from the internet. Source: Cyber Security News

Networking

HPE widens Juniper networking access via new distributor deal

HPE named D&H Distributing a North American distributor for its full HPE Networking portfolio, including HPE Juniper Networking routers and switches, with full reseller availability by end of September. It's the latest step folding Juniper's go-to-market into HPE's broader channel. What it means: if you buy networking gear through a smaller regional reseller, ask whether they carry the expanded HPE/Juniper line through D&H, and confirm pricing and support terms as the merged catalog settles. Source: GlobeNewswire

Security

CISA flags exploited Check Point, F5 and Arista VeloCloud flaws

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, covering Check Point management servers and Spark firewalls, F5 BIG-IP APM and Arista VeloCloud Orchestrator. Check Point reports a small number of customers were attacked. What it means: if you run any of these firewall managers, access gateways or SD-WAN orchestrators, patch now, limit management access to trusted addresses, and review logs for unusual administrator logins. Source: Help Net Security

Security · AI

Palo Alto turns AI attack testing into a subscription

Unit 42 Continuous Frontier AI Defense uses frontier models from Anthropic and OpenAI to probe an environment continuously, confirm which weaknesses are truly exploitable and guide fixes. Palo Alto says early engagements found exposures in every environment tested. What it means: continuous, AI-driven testing is replacing the once-a-year pen test for teams that can't staff a red team. Ask how it's priced and scoped before you budget for it. Source: Palo Alto Networks

Security

CISA warns of mass exploitation of a Zyxel switch flaw

CISA added a stack-based buffer overflow in Zyxel's GS1900-series smart-managed switches to its Known Exploited Vulnerabilities catalog. An attacker has exploited it since mid-August to run unauthenticated commands on nearly 1,000 unpatched switches worldwide, pulling configs and password hashes. Zyxel shipped a fix in June; adoption has lagged. What it means: GS1900 switches are a common budget pick in school, library and small-city network closets; check firmware now, since an attacker already on the network can fully take over an unpatched switch. Source: CISA

E-Rate

E-Rate's fall deadlines land, and payments now run through SAM.gov

USAC's administrative window for FY2027 opens Oct 21; FY2026 Form 486 is due Oct 29 and FY2025 recurring-service invoices Oct 28. Since Sep 8, E-Rate reimbursements use SAM.gov banking data. What it means: districts and libraries should confirm an active SAM.gov registration now, or reimbursements can stall, and put the Oct 21 to 29 dates on the calendar. Source: USAC

Networking · Security

Cisco patches 18 Secure Firewall flaws, eight rated critical

Cisco's September bundle for Secure Firewall ASA, FTD and Management Center fixes 18 vulnerabilities, several allowing unauthenticated remote code execution. There are no workarounds; the fix is an upgrade. What it means: schedule firewall upgrades now, starting with Management Center, which attackers already targeted earlier this month. Source: Cisco