Skip to main content

Check Point, Arista, and F5: Four Perimeter Vulnerabilities Exploited in a Single Day

CISA has added four vulnerabilities exploited without authentication in network equipment from Check Point, Arista VeloCloud, and F5 BIG-IP in a single update. Notable is CVE-2026-93616, a critical path traversal in Check Point management servers.

CybersecuritySeintec team3 min read
Check Point, Arista, and F5: Four Perimeter Vulnerabilities Exploited in a Single Day

News summary

On 22 September 2026, CISA added four actively exploited flaws in perimeter equipment from three vendors to its Known Exploited Vulnerabilities catalogue: a pre-authentication remote code execution in Check Point Security Gateway VPN (CVE-2026-85102), a path traversal in Check Point management servers (CVE-2026-93616), a validation flaw in Arista VeloCloud Orchestrator with a CVSS 10 rating (CVE-2026-93952), and a buffer overflow in F5 BIG-IP Access Policy Manager.

CVE-2026-93616, carrying a CVSS 9.8 score, allows an unauthenticated attacker to upload and execute arbitrary scripts. It affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Check Point has released its official advisory detailing the affected versions and fixes.

The significance lies not in each individual flaw, but in the pattern: all reside in devices that terminate VPNs, manage remote access, or orchestrate SD-WAN. Industry analysts note that, regarding Check Point, exploitation attempts surfaced within days of the patches being released.

Compromising a firewall's management or logging console is particularly severe: an attacker can modify policies whilst simultaneously reducing the security team's visibility. Consequently, after patching, it is essential to investigate whether prior activity occurred and to preserve evidence.

Source: CiberPlaneta — 22 September 2026

Frequently Asked Questions

Why are attackers targeting perimeter devices?
Because they are internet-facing by design, control access to the internal network, and, in these instances, can be attacked without credentials. A single flaw provides access to the entire organisation.
What is a reasonable timeframe for patching?
CISA set a three-day deadline for federal agencies to address CVE-2026-93616. This serves as a reliable urgency benchmark for any business with affected exposed equipment.

Concepts mentioned in this article: Cloud · Firewall

Your network perimeter is your first line of defence and currently the primary target. At Seintec, we manage and update firewalls and VPN and review their exposure. Speak with our cybersecurity team.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.