U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability
- CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability
- CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks and run their own code on the gateway. In mid-September, the Dutch NCSC warned that this critical flaw could soon be actively exploited. If you use Check Point VPN, you should patch it immediately.
Check Point addressed the flaws on September 9 with the release of the advisories sk1000117 and sk1000118. The affected releases span R81.20, R82, R82.10, R81.10.x and R82.00.x, plus end‑of‑support versions from R80 through R81.10. R82.20 is not affected. For supported versions, Check Point provides fixes through LivePatch Take 24 or specific Jumbo Hotfix updates, depending on the version you use.
CVE-2026-93616 is a critical path traversal flaw in its Security Management Server. Attackers can abuse the flaw without logging in to upload malicious scripts and execute them on vulnerable servers. Because the Management Server controls security policies, admin activity and system logs across Check Point deployments, a compromise could have a wider impact on an enterprise network.
The vulnerability affects more than Check Point’s main Security Management Server. The impacted products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Check Point fixed the issue in the R82.20 Security Hotfix and is urging customers to act quickly.
The company revealed the flaw “is exploited in the wild” and that it is aware of a handful of customers who have already been attacked. The actual number of victims could be higher, since some compromises may go undetected or never be reported to Check Point. The company has also published indicators of compromise (IOCs) in its advisory, giving security teams a way to check their systems and logs for signs of an attack.
CVE-2026-93952 affects VeloCloud Orchestrator (VCO) on-premises deployments. The flaw may let a remote attacker access privileged internal functionality and impact the VCO host. Successful exploitation could compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages. Hosted VCO environments, including Dedicated versions, were also affected but have already been patched. Organizations running on-premises VCO should apply the available security updates.
The flaw CVE-2026-94127 affects BIG-IP Access Policy Manager (APM) and allows an unauthenticated attacker to execute arbitrary code on a vulnerable BIG-IP system. F5 disclosed the issue on September 22 and confirmed that exploitation had already been observed.
The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server. More specifically, the vulnerable configuration is one in which APM operates as an OAuth Authorization Server. Systems using APM only as an OAuth Client or Resource Server are not affected.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the flaws by September 25, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, CISA)

