What happened
CISA's September 22 alert added four entries to the Known Exploited Vulnerabilities catalog: two in Check Point products, one in F5 BIG-IP APM and one in Arista VeloCloud Orchestrator (an improper input validation flaw this post does not cover). The federal remediation deadline for the three covered here is September 25.
F5 BIG-IP APM: CVE-2026-94127
F5 published advisory K000162605 on September 22 for a heap-based buffer overflow in BIG-IP Access Policy Manager. Specific traffic sent to an affected virtual server can lead to remote code execution without authentication. It is scored 9.8 on CVSS 3.1 and 9.3 on CVSS 4.0. The flaw is only reachable when an APM access policy and an OAuth authorization server profile are configured on the same virtual server; systems using APM only as an OAuth client or resource server are not affected, and the default configuration is not vulnerable. F5's advisory states: "We have learned that this vulnerability has been exploited." Public reporting has not named who is behind the attacks.
Affected releases are 21.1.0, 17.5.0 to 17.5.1 and 17.1.0 to 17.1.3. F5 has released engineering hotfixes for each branch (listed in the facts box above) and offers an iRule mitigation through F5 Support for customers who cannot install a hotfix immediately. Shadowserver tracks over 14,700 IP addresses with BIG-IP APM fingerprints online, according to BleepingComputer; how many are configured as an OAuth authorization server is not known.
Check Point: CVE-2026-85102 and CVE-2026-93616
Check Point disclosed CVE-2026-85102 and shipped fixes on September 9. It is
"improper validation of certificate data during VPN negotiation" that allows unauthenticated remote
code execution on Security Gateway and on Spark firewalls, CVSS 9.8. Check Point says active
exploitation began on September 12, targeting Spark customers, from anonymization infrastructure
such as VPN services and proxies. The attacks used client certificates with subjects such as
CN=vpn,OU=users,O=global (BleepingComputer also lists CN=vpn-user and
CN=vpnuser variants).
CVE-2026-93616, disclosed on September 22, is a pre-authentication path traversal in the Security Management web service that lets an attacker execute a script from an arbitrary path and load an arbitrary Java class (CVSS 9.8). Check Point says it saw "a handful of pinpointed attacks" using it on July 23, 2026, two months before the advisory, which makes it a zero-day with a fix released the same day as the disclosure.
Why it matters if you run public infrastructure
All three bugs are in products whose job is to face the internet: an access gateway, a VPN gateway, and the management server that controls the firewalls. All three are reachable without credentials. A compromised VPN gateway or firewall manager is not one more host to clean up; it is the device that was supposed to keep everything else out, and it usually sees credentials in transit. This is not the first edge appliance this month to go from advisory to exploitation within days (see NetScaler CVE-2026-19490), and in Check Point's management case the attacks came first.
What to check this week
- Inventory your edge devices from the outside. List every host under your domains that answers as a BIG-IP virtual server, a Check Point VPN or Mobile Access portal, or a management web interface. Include appliances in branch offices and ones set up by a previous team.
- F5: check whether any virtual server combines an APM access policy with an OAuth authorization server profile. If so, install the hotfix for your branch or apply F5's iRule mitigation now. If you run APM only as an OAuth client or resource server, record that and move on.
- Check Point gateways: confirm every Security Gateway and Spark appliance is on the Jumbo Hotfix take or Spark build listed in the advisory, and review Mobile Access and VPN logs for certificate-based logins with the subjects above, and for internal scanning that followed.
- Check Point management: make sure the Security Management web service is not reachable from the internet, and apply the September 22 hotfix. Because exploitation predates the advisory by two months, investigate for compromise back to July.
- Plan for end-of-support versions. Check Point R80 to R81 are end of support, so exposed gateways on those versions need upgrading or isolating. If you run a BIG-IP branch outside the three F5 lists, confirm its support status with F5.
How Attack Surface Scan covers this
Honestly, partially. F5 BIG-IP and Check Point are not in the product catalog our vulnerability matching recognizes today, so we will not raise a CVE finding for these three. What we do provide is the outside-in inventory those checks start from: every host under your verified domains (including ones discovered through certificate transparency logs), the ports and web services each one exposes, the certificates they present, and an alert when a new listener or login page appears. That tells you where your VPN and access gateways are; the version and configuration checks above still have to happen on the devices. For the edge products we do recognize, such as NetScaler, FortiOS SSL-VPN, Ivanti Connect Secure and GlobalProtect, see Vulnerability matching.
Sources
- CISA: CISA Adds Four Known Exploited Vulnerabilities to Catalog (September 22, 2026)
- F5: K000162605, BIG-IP APM vulnerability CVE-2026-94127
- Check Point: Security Advisory, Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616
- The Hacker News: F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
- BleepingComputer: F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
- BleepingComputer: Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
- Qualys ThreatPROTECT: CISA Warns of Check Point Vulnerabilities Exploited in Attacks