Ethical Hacking News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several critical vulnerabilities to its Known Exploited Vulnerabilities catalog, including Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM. These vulnerabilities pose a significant risk to national security and are being actively exploited. Experts urge organizations to patch these vulnerabilities as soon as possible to prevent further exploitation and potential attacks. The added vulnerabilities serve as a reminder of the ongoing threat landscape and the need for continued vigilance in maintaining the security of our digital infrastructure.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added several critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerabilities are related to Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM, and are classified as critical. The Check Point vulnerabilities allow unauthenticated attackers to bypass security checks and run their own code on the gateway. The Arista VeloCloud Orchestrator vulnerability allows a remote attacker to access privileged internal functionality. The F5 BIG-IP APM vulnerability allows an unauthenticated attacker to execute arbitrary code on a vulnerable BIG-IP system. Federal agencies and private organizations are required to address the identified vulnerabilities by the due date to protect their networks against attacks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added several vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, which is a database of actively exploited vulnerabilities that pose a significant risk to national security. The added vulnerabilities are related to Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM, and are classified as critical.
The Check Point vulnerabilities, identified as CVE-2026-85102 and CVE-2026-93616, are related to improper certificate validation and path traversal, respectively. The former vulnerability, CVE-2026-85102, resides in the VPN negotiation process and allows an unauthenticated attacker to bypass security checks and run their own code on the gateway. This vulnerability was first disclosed by the Dutch National Cyber Security Centre (NCSC) in mid-September, and is already being actively exploited.
The second Check Point vulnerability, CVE-2026-93616, is a critical path traversal flaw in the Security Management Server, which allows attackers to upload malicious scripts and execute them on vulnerable servers. This vulnerability affects not only the main Security Management Server but also other impacted products, such as Multi-Domain Security Management Server, Log Server, and SmartEvent.
In contrast, the Arista VeloCloud Orchestrator vulnerability, CVE-2026-93952, is related to improper input validation, which may allow a remote attacker to access privileged internal functionality and impact the VCO host. Organizations running on-premises VCO deployments are advised to apply available security updates to patch this vulnerability.
The F5 BIG-IP APM vulnerability, CVE-2026-94127, is a heap-based buffer overflow vulnerability that allows an unauthenticated attacker to execute arbitrary code on a vulnerable BIG-IP system. This vulnerability was first disclosed by F5 on September 22, and is already being actively exploited.
According to the Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, federal agencies are required to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog. Private organizations are also advised to review the Catalog and address the vulnerabilities in their infrastructure.
Experts emphasize the importance of patching these vulnerabilities as soon as possible to prevent further exploitation and potential attacks. The added vulnerabilities to the KEV catalog serve as a reminder of the ongoing threat landscape and the need for continued vigilance in maintaining the security of our digital infrastructure.
Related Information:
https://www.ethicalhackingnews.com/articles/US-CISA-Adds-Check-Point-Arista-VeloCloud-Orchestrator-and-F5-BIG-IP-APM-Vulnerabilities-to-Known-Exploited-Vulnerabilities-Catalog-ehn.shtml
https://securityaffairs.com/199631/hacking/u-s-cisa-adds-check-point-arista-velocloud-orchestrator-and-f5-big-ip-apm-flaws-to-its-known-exploited-vulnerabilities-catalog.html
https://nvd.nist.gov/vuln/detail/CVE-2026-85102
https://www.cvedetails.com/cve/CVE-2026-85102/
https://nvd.nist.gov/vuln/detail/CVE-2026-93616
https://www.cvedetails.com/cve/CVE-2026-93616/
https://nvd.nist.gov/vuln/detail/CVE-2026-93952
https://www.cvedetails.com/cve/CVE-2026-93952/
https://nvd.nist.gov/vuln/detail/CVE-2026-94127
https://www.cvedetails.com/cve/CVE-2026-94127/
Published: Wed Sep 23 17:32:14 2026 by llama3.2 3B Q4_K_M