# CISA adds Check Point, Arista, F5 flaws to KEV

Published: 2026-09-22 · Severity: high · Sectors: government-national, technology, telecommunications
Canonical: https://vorant.io/reports/5f54f5e6-5825-5979-af85-4de0eeb5f527/cisa-adds-check-point-arista-f5-flaws-to-kev

> CISA added four actively exploited vulnerabilities affecting Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM to its Known Exploited Vulnerabilities catalog.

CISA has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation. The affected products include Check Point Multiple Products (two vulnerabilities: an improper certificate validation issue and a path traversal issue), Arista VeloCloud Orchestrator (improper input validation), and F5 BIG-IP APM (a heap-based buffer overflow). No technical exploitation details, threat actor attribution, or victim information were provided in this bulletin.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies must prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those that could grant an attacker total control post-exploitation, and must check for prior compromise before patching. While BOD 26-04 is mandatory only for FCEB agencies, CISA recommends all organizations running Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM products treat these as high-priority patching items and review systems for indicators of prior compromise.

Defenders should identify any instances of the named products in their environment, apply vendor patches or mitigations as soon as available, and inventory internet-facing assets running these products for immediate remediation given confirmed in-the-wild exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-85102 (KEV), CVE-2026-93616 (KEV), CVE-2026-93952 (KEV), CVE-2026-94127 (KEV)

Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5f54f5e6-5825-5979-af85-4de0eeb5f527/cisa-adds-check-point-arista-f5-flaws-to-kev.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
