Search
Find merged stories by title or summary.
U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability • CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability • CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability • CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks and run their own code on the gateway.
Arista Networks security advisory (AV26-947)
Serial number: AV26-947 Date: September 22, 2026 As of September 22, 2026, Arista Networks is affected by a vulnerability in the following product: • VeloCloud Orchestrator (VCO) On-Prem • Versions 5.2.0 to 5.2.3.15 • Versions 6.1.0 to 6.1.3.7 • Versions 6.4.0 to 6.4.2.7 • Versions 7.0.0 to 7.0.0.2 Open-source reporting indicates that CVE-2026-93952 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. • Security Advisory 0183 • Arista Networks Advisories & Notices Arista Networks security advisory (AV26-947) - Canadian Centre for Cyber Security
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability • CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability • CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability • CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
[CISA] CVE-2026-93952 - Confirmed Exploitation
CVE-2026-93952 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-09-22 00:00 UTC Evidence Sources: 1 First Seen: 2026-09-22 Asserted: 2026-09-22
You've reached the end of current stories for this search.
