securityaffairs.com 23 Sept 2026, 20:37 UTC

CISA Warns of Active Attacks on Check Point and F5 Flaws

CISA Warns of Active Attacks on Check Point and F5 Flaws

THE US Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue: Check Point flaws CVE-2026-85102 and CVE-2026-93616, Arista VeloCloud Orchestrator CVE-2026-93952, and F5 BIG-IP Access Policy Manager (APM) CVE-2026-94127. Under Binding Operational Directive 22-01, US federal civilian agencies must address them by 25 September 2026; CISA also recommends that private-sector organisations review and remediate affected systems.

CVE-2026-85102 affects Check Point’s VPN negotiation process and can allow an unauthenticated attacker to bypass security checks and execute code on a gateway. Check Point issued fixes on 9 September for affected releases including R81.20, R82, R82.10, R81.10.x and R82.00.x, while R82.20 is not affected. CVE-2026-93616 is an unauthenticated path-traversal vulnerability affecting Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent.

Attackers can upload scripts and execute them; Check Point said the flaw is being exploited in the wild and that a handful of customers had been attacked. Indicators of compromise are available in its advisory, and the company urges immediate action.

CVE-2026-93952 affects on-premises VeloCloud Orchestrator and may expose privileged internal functionality; hosted environments have already been patched. CVE-2026-94127 is an unauthenticated heap-based buffer overflow in BIG-IP APM that can enable arbitrary code execution. F5 said exploitation had been observed, but the affected configuration requires an access policy and OAuth profile with APM operating as an OAuth Authorisation Server; OAuth Client or Resource Server deployments are not affected.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline