Cybersecurity 5 min read

Four Exploited Appliance Flaws, and the Deadline Is Today

Security appliances from Arista, F5 and Check Point are being attacked, and United States agencies must patch them by today. One flaw scores the maximum 10.0.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 25 Sep 2026, 11:01 PM (SGT)
Share:
A rack-mounted network appliance with amber status lights in a dim equipment room A rack-mounted network appliance with amber status lights in a dim equipment room AI generated
Advertisement

25 SEP 2026 — Federal agencies have until today, 25 September, to fix four security-appliance flaws from three vendors, added to the United States exploited-vulnerability list on 22 September. All four are already being used.

One of them carries a CVSS of 10.0, and two of its four release trains still have no patch.

What CISA added and when

The four are two Check Point flaws, one in Arista's VeloCloud Orchestrator and one in F5's BIG-IP Access Policy Manager. CISA added them on 22 September under Binding Operational Directive 26-04, with a remediation date of 25 September.

Three days is short even by the directive's standards. CISA publishes no severity scores in the alert and no detail of who is exploiting what; it says only that the additions rest on evidence of active exploitation.

The four products share no common technology. They share a job: all are bought to keep attackers out of a network.

Arista scored a perfect ten

CVE-2026-93952 in VeloCloud Orchestrator carries a CVSS 3.1 base score of 10.0, the maximum. Arista's advisory describes improper input validation reachable over the network, at low complexity, needing no privileges and no user interaction.

Not every VeloCloud Orchestrator is vulnerable. The orchestrator must be configured for certificate-based authentication from a VeloCloud Edge, and the attacker needs network access to its web interface plus the public half of an Edge certificate. Tenant or operator credentials are not required.

Affected trains are 5.2.3.15 and below, 6.1.3.7 and below, 6.4.2.7 and below, and 7.0.0.2 and below. Fixes exist for two of them: 5.2.3.16 and 6.4.2.8. The 6.1 and 7.0 trains are still waiting.

Most vendors do not publish indicators of compromise. Arista did. The list includes two file paths under /usr/local/sbin, a systemd unit, an x-vc-opt header in nginx logs, two addresses and a file hash. A defender can hunt with that.

10.0CVSS base score for the Arista flaw
2 of 4VeloCloud trains with a fix available
25 SeptFederal remediation deadline
12 SeptWhen Check Point saw exploitation begin

The F5 flaw needs one setting

CVE-2026-94127 is a heap-based buffer overflow in BIG-IP Access Policy Manager, scored 9.8, giving unauthenticated remote code execution to anyone who can reach an affected virtual server.

It is narrow. The virtual server has to carry both an access policy and an OAuth profile at once, which is not a default. Where that combination exists the overflow sits in the traffic-handling data plane rather than the management interface, so restricting administrative access does not help.

Rapid7 noted that as of 22 September no public proof of concept had been confirmed. The flaw is on the exploited list all the same, so someone has one.

Check Point, again, and worse

CVE-2026-85102 is the certificate-validation flaw in VPN negotiation that was patched on 9 September. Check Point now reports that from 12 September it observed a wave of exploitation attempts against Spark customers globally, and it lists three certificate subject names seen in those attempts.

Advertisement

The second flaw, CVE-2026-93616, is a pre-authentication path traversal in the management web service that allows a script to be run from an arbitrary path and an arbitrary Java class to be loaded. It is a zero-day, also scored 9.8, which the company says was used in a handful of pinpointed attacks on 23 July.

The date worth pausing on is 23 July, two months before the disclosure.

The warning we reported came true

On 14 September this desk reported that the Dutch national cyber security centre had warned about the Check Point VPN flaws before anyone had seen them exploited. The patch landed on the 9th, the warning on the 12th, with no public exploit code and no observed exploitation at that point.

Check Point dates the first wave to 12 September, the same day the warning was issued.

The Dutch were right. Being right bought about seventy-two hours. Anyone who patched on the strength of that warning had that much time in hand; anyone who waited for confirmation of exploitation was already inside the window.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement