Skip to content
Tech CEO Daily
CybersecurityCyber Alert

Exploited flaws hit Check Point, F5 and Arista network gear in one day

CISA flagged four actively exploited bugs in firewalls, VPNs, access gateways and SD-WAN management tools, three of them rated 9.8 or higher.

TC

By Tech CEO Daily Staff, Newsroom

· 2 min read

Rows of enterprise firewalls and network switches with blinking lights in a telecom room
AI-generated image for illustration. Not a photograph of the events described.

The news

CISA on September 22 added four vulnerabilities to its Known Exploited Vulnerabilities catalog, all in network infrastructure that sits between companies and the internet: two in Check Point products, one in Arista’s VeloCloud Orchestrator and one in F5’s BIG-IP Access Policy Manager.

Check Point’s CVE-2026-85102 (CVSS 9.8) involves improper certificate validation during VPN negotiation and can let an unauthenticated attacker run code on Security Gateways and Spark firewalls. The company says exploitation on Spark firewalls was confirmed as of September 12. A second flaw, CVE-2026-93616 (CVSS 9.8), allows unauthenticated file upload and script execution on Check Point management and log servers; Check Point said it is aware of “a handful of customers who have been attacked.” Jumbo Hotfix updates are available, and many older affected versions are past end of support.

F5 disclosed CVE-2026-94127 (CVSS 9.8), a heap buffer overflow in BIG-IP APM, on September 22 and confirmed exploitation. SecurityWeek reported that it affects versions 21.1.0, 17.5.0–17.5.1 and 17.1.0–17.1.3 only where APM acts as an OAuth Authorization Server, and that F5 has shipped hotfixes. Restricting access to the management interface does not help, because attacks target the virtual server itself.

Arista rated CVE-2026-93952 in on-premises VeloCloud Orchestrator a 10.0 and said it is known to be actively exploited. It affects systems using certificate-based authentication with a reachable web interface. Hosted orchestrators were already patched; fixed on-premises releases include 5.2.3.16 and 6.4.2.8.

The numbers

Arista VeloCloud CVSS v3.1
10.0
Check Point and F5 CVSS
9.8
Exploitation seen on Check Point Spark since
Sept 12, 2026
Flaws added to CISA KEV
4

Why CEOs should care

Firewalls, VPN concentrators and SD-WAN controllers are prime targets because they are internet-facing and trusted by everything behind them. Ask your network team, and any managed security provider, for a same-week inventory: which of these products you run, whether they are on fixed builds, and whether any are past end of support and need replacing rather than patching.

Vendors have published indicators of compromise; Arista, for example, lists suspicious files, headers and IP addresses. Patching should be paired with a check for signs of intrusion, since exploitation began before some fixes were widely deployed.

The bigger picture

This batch, together with the Citrix NetScaler zero-days that followed days later, reinforces a pattern: perimeter appliances are being hit faster than many organisations can patch them, making asset inventories and end-of-life replacement plans a board-level resilience issue.

Sources

TC
Tech CEO Daily Staff

Newsroom

Reporting and analysis from the Tech CEO Daily newsroom. Each story is researched from primary sources — company announcements, regulatory filings and official advisories — and fact-checked before publication.

Spotted an error? Request a correction. Read our editorial standards and AI policy.

The Daily Brief

The technology briefing for people running businesses.

Weekdays at 6 a.m. ET. Free.

More in Cybersecurity