← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 23, 2026 · 20:37via Security Affairs

U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog

Brief

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog.

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog :

  • CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability
  • CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability
  • CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
  • CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks and run their own code on the gateway.

Read more on Security Affairs