Check Point, Arista, and F5: Four Perimeter Vulnerabilities Exploited in a Single Day
CISA has added four vulnerabilities exploited without authentication in network equipment from Check Point, Arista VeloCloud, and F5 BIG-IP in a single update. Notable is CVE-2026-93616, a critical path traversal in Check Point management servers.

News summary
On 22 September 2026, CISA added four actively exploited flaws in perimeter equipment from three vendors to its Known Exploited Vulnerabilities catalogue: a pre-authentication remote code execution in Check Point Security Gateway VPN (CVE-2026-85102), a path traversal in Check Point management servers (CVE-2026-93616), a validation flaw in Arista VeloCloud Orchestrator with a CVSS 10 rating (CVE-2026-93952), and a buffer overflow in F5 BIG-IP Access Policy Manager.
CVE-2026-93616, carrying a CVSS 9.8 score, allows an unauthenticated attacker to upload and execute arbitrary scripts. It affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Check Point has released its official advisory detailing the affected versions and fixes.
The significance lies not in each individual flaw, but in the pattern: all reside in devices that terminate VPNs, manage remote access, or orchestrate SD-WAN. Industry analysts note that, regarding Check Point, exploitation attempts surfaced within days of the patches being released.
Compromising a firewall's management or logging console is particularly severe: an attacker can modify policies whilst simultaneously reducing the security team's visibility. Consequently, after patching, it is essential to investigate whether prior activity occurred and to preserve evidence.
Source: CiberPlaneta — 22 September 2026
Frequently Asked Questions
- Why are attackers targeting perimeter devices?
- Because they are internet-facing by design, control access to the internal network, and, in these instances, can be attacked without credentials. A single flaw provides access to the entire organisation.
- What is a reasonable timeframe for patching?
- CISA set a three-day deadline for federal agencies to address CVE-2026-93616. This serves as a reliable urgency benchmark for any business with affected exposed equipment.
Concepts mentioned in this article: Cloud · Firewall
Your network perimeter is your first line of defence and currently the primary target. At Seintec, we manage and update firewalls and VPN and review their exposure. Speak with our cybersecurity team.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.