VYPR
advisoryPublished Sep 23, 2026· 1 source

Check Point and F5 BIG-IP APM Devices Targeted by Zero-Day Exploits

Check Point and F5 BIG-IP APM devices are under active attack due to newly disclosed zero-day vulnerabilities, prompting emergency patches and CISA alerts.

Check Point Software has issued urgent patches for a critical vulnerability, CVE-2026-93616, affecting its Management Servers. This flaw, a pre-authentication path traversal vulnerability in the web service, has been exploited by attackers since at least July 23, 2026. The vulnerability allows adversaries to upload and execute arbitrary scripts on affected servers, including Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Check Point has confirmed a small number of customer attacks and provided indicators of compromise, while also offering a mitigation strategy of restricting Management Server access to trusted internal IP addresses for those unable to apply hotfixes immediately.

Adding to the urgency, a separate pre-authentication remote code execution (RCE) vulnerability, CVE-2026-85102, in Check Point Security Gateway products, particularly affecting Check Point Spark Firewalls, has also seen exploitation attempts. While patches were released on September 9, 2026, Check Point observed a surge in probing attempts starting September 12, originating from anonymization infrastructure like VPNs and proxies. The company advises customers to install the fix immediately and review logs for anomalous certificate-based Mobile Access logins and subsequent internal scanning activity.

These vulnerabilities are not isolated incidents. Both CVE-2026-93616 and CVE-2026-85102 were added to the CISA's Known Exploited Vulnerabilities (KEV) catalog, alongside two other critical flaws. One of these, CVE-2026-93952, impacts Arista's VeloCloud Orchestrator, the management platform for VeloCloud SD-WAN. The other, CVE-2026-94127, is a critical RCE vulnerability in F5 Networks' BIG-IP APM (Access Policy Manager) when configured as an OAuth Authorization Server, allowing unauthenticated attackers to execute arbitrary code.

The inclusion of these four vulnerabilities in the KEV catalog signifies active, widespread exploitation. CISA has mandated that U.S. civilian federal agencies address all four flaws by September 25, 2026, and has instructed them to check their systems for signs of compromise. The directive extends to the private sector, urging similar vigilance and prompt remediation.

The F5 BIG-IP APM vulnerability, CVE-2026-94127, specifically allows an unauthenticated attacker to achieve RCE by sending malicious network traffic to the system. This highlights a significant risk for organizations relying on F5's BIG-IP APM for access management, especially when it's configured to use OAuth. Details on the specific attacks remain limited, but vendors have provided indicators of compromise to aid detection.

Check Point Spark firewalls, targeted by CVE-2026-85102, are designed for small to medium-sized businesses and managed service providers. The exploitation of these devices underscores the broad reach of the current attack campaigns, affecting a wide spectrum of organizations. The use of anonymization infrastructure suggests a concerted effort by threat actors to obscure their origins.

Arista's VeloCloud Orchestrator, affected by CVE-2026-93952, is a crucial component for managing SD-WAN deployments. Exploitation of this platform could lead to widespread network disruption or compromise across organizations utilizing VeloCloud technology.

This coordinated targeting of critical network and security infrastructure by multiple threat actors underscores a growing trend of exploiting zero-day vulnerabilities in widely deployed products. The rapid addition to CISA's KEV catalog and the subsequent emergency directives emphasize the severity and immediate threat posed by these flaws, requiring swift action from organizations worldwide to secure their environments.

Synthesized by Vypr AI
Check Point and F5 BIG-IP APM Devices Targeted by Zero-Day Exploits · VYPR