# CERT-FR flags actively exploited flaws in Check Point, F5, Citrix, WSO2

Published: 2026-09-28 · Severity: severe · Sectors: technology, infrastructure, telecommunications
Canonical: https://vorant.io/reports/a6a26406-6fb3-5c19-b669-2640466a69a6/cert-fr-flags-actively-exploited-flaws-in-check-point-f5-citrix-wso2

> CERT-FR's weekly bulletin lists actively exploited critical RCE flaws in Check Point, F5 BIG-IP, WordPress, Citrix NetScaler, WSO2, Arista VeloCloud and more, urging urgent patching.

This is CERT-FR's regular weekly vulnerability bulletin (week 39, 21-27 September 2026) summarizing the most significant vulnerabilities disclosed and patched that week, with emphasis on those already under active exploitation. Multiple critical (CVSS 9.3-9.9) remote code execution and security-bypass flaws affect widely deployed enterprise products: Check Point Multi-Domain Security Management/Security Management (CVE-2026-93616, CVE-2026-91843), F5 BIG-IP APM (CVE-2026-94127), WordPress core (CVE-2026-87902, the 'Click2Shell' RCE requiring an admin to submit a malicious form), GitLab CE/EE (CVE-2026-89078, CVE-2026-93577), SolarWinds Observability Self-Hosted (CVE-2026-28324) and Serv-U (CVE-2026-28308), HPE Aruba Networking Analytics and Location Engine (CVE-2026-76708/76709), Synology DSM (CVE-2026-13639, CVE-2026-13684), and Apache Tomcat (CVE-2026-86248, CVE-2026-76183, CVE-2026-86350). Check Point, F5 and WordPress vulnerabilities are confirmed exploited in the wild; most others show no public exploitation information yet.

A secondary table lists additional actively exploited vulnerabilities tracked outside the main critical table: WSO2 Traffic Manager/API Manager/Universal Gateway (CVE-2026-5430, CVSS 10, security bypass), Arista VeloCloud Orchestrator (CVE-2026-93952), Citrix NetScaler ADC/Gateway (CVE-2026-88771 and related CVEs, RCE and security bypass), Zyxel GS1900 series switch firmware (CVE-2026-7273, buffer overflow RCE), Microsoft SharePoint Server (CVE-2026-65660), Roundcube Webmail (CVE-2026-48842, SQLi), Veeam Backup & Replication (CVE-2026-32996, privilege escalation), MikroTik RouterOS (CVE-2026-67279), and Foxit PDF Editor/Reader (CVE-2026-91799, public exploit code available). The bulletin also enumerates ~27 separate CERT-FR advisories issued that week covering Mattermost, Microsoft Edge, Moodle, Chrome, Wireshark, LibreNMS, PaperCut, Microsoft Office, Zabbix Agent, PHP, Elastic products, and Linux kernel updates across Ubuntu, Red Hat, SUSE and Debian LTS, plus updates to older advisories on Siemens products and Microsoft SharePoint.

Defenders should prioritize patching Check Point Security Management/Multi-Domain, F5 BIG-IP APM, WordPress (upgrade directly to 7.1.2 to cover both CVE-2026-87902 and the Click2Shell issue), Citrix NetScaler, and WSO2 products given confirmed in-the-wild exploitation, then work through the remaining critical RCE and security-bypass items (GitLab, Aruba, Synology, Tomcat, SolarWinds) per vendor advisories referenced in each CERT-FR AVI bulletin.

## Mentioned in this report

- Vulnerabilities: CVE-2026-13639, CVE-2026-13684, CVE-2026-28308, CVE-2026-28324, CVE-2026-32996, CVE-2026-48842, CVE-2026-5430 (KEV), CVE-2026-65660 (KEV), CVE-2026-67279 (KEV), CVE-2026-7273 (KEV), CVE-2026-76183, CVE-2026-76708, CVE-2026-76709, CVE-2026-86248, CVE-2026-86350, CVE-2026-87902 (KEV), CVE-2026-88771 (KEV), CVE-2026-89078, CVE-2026-91799, CVE-2026-91843, CVE-2026-93577, CVE-2026-93616 (KEV), CVE-2026-93952 (KEV), CVE-2026-94127 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-041

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a6a26406-6fb3-5c19-b669-2640466a69a6/cert-fr-flags-actively-exploited-flaws-in-check-point-f5-citrix-wso2.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
