Skip to main content
Edge SecurityVulnerability Patch· 4 min read· in Technology

CISA Mandates Rapid Patching for Four Actively Exploited Edge Vulnerabilities

The Cybersecurity and Infrastructure Security Agency has added four zero-day flaws affecting Check Point, Arista, and F5 edge devices to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply fixes by September 25.

By Diego Navarro

Federal Regulators 40%Network Hardware Vendors 30%Enterprise Security Defenders 30%
Federal Regulators
Focuses on rapid remediation and strict compliance deadlines to secure national infrastructure.
Network Hardware Vendors
Emphasizes specific configuration conditions that trigger the flaws and the immediate deployment of emergency hotfixes.
Enterprise Security Defenders
Highlights the operational challenge of patching edge devices without disrupting remote workforce connectivity.

Perspectives this story doesn't cover

  • Independent Security Researchers

How we got here

  1. July 2026

    Attackers begin probing the Check Point management server vulnerability in targeted strikes.

  2. Sep 9, 2026

    Check Point releases initial patches for the Security Gateway remote code execution flaw.

  3. Sep 22, 2026

    CISA adds the four zero-day vulnerabilities to its Known Exploited Vulnerabilities catalog.

  4. Sep 25, 2026

    Deadline for U.S. federal civilian agencies to apply the required vendor hotfixes.

Why it matters

Edge devices sit between the open internet and internal corporate networks, making them prime targets for attackers. Rapid patching of these specific vulnerabilities prevents unauthorized remote code execution and secures both federal and private sector infrastructure against ongoing exploitation.

When a single edge appliance vulnerability surfaces, network administrators typically schedule a maintenance window to apply the fix without disrupting remote workers. The September 22 update to the Known Exploited Vulnerabilities (KEV) catalog differs by clustering four separate zero-day flaws across three major vendors—Check Point, Arista, and F5 Networks—triggering an immediate 72-hour patching mandate from the Cybersecurity and Infrastructure Security Agency (CISA).[1][4]

The directive, issued under Binding Operational Directive (BOD) 26-04, requires all Federal Civilian Executive Branch agencies to remediate the vulnerabilities by September 25, 2026. While the mandate technically applies only to federal networks, CISA strongly urges private sector organizations to adopt the exact same timeline. The agency confirmed that all four vulnerabilities are currently being exploited in the wild, elevating the response from routine maintenance to an active incident containment effort.[1][2]

The most severe of the four additions is CVE-2026-94127, a heap-based buffer overflow in the F5 BIG-IP Access Policy Manager (APM). The flaw carries a CVSS 3.1 severity score of 9.8 out of 10 and allows an unauthenticated attacker to execute arbitrary code on the affected appliance. Because the BIG-IP system often serves as the primary gateway for enterprise traffic, a successful exploit grants total control over the network perimeter.[3][4]

F5 clarified the specific conditions required for the exploit to function. The vulnerability only triggers on virtual servers configured to act as an OAuth Authorization Server. Deployments using the APM strictly as an OAuth Client or Resource Server remain unaffected. F5 released emergency hotfixes on September 22, confirming that threat actors were already exploiting the code path before the public advisory went live.[3][4]

Severity scores for the newly listed edge device vulnerabilities.

Arista Networks also issued urgent patches for CVE-2026-93952, an improper input validation issue in its VeloCloud Orchestrator. The platform serves as a centralized management tool for configuring, monitoring, and orchestrating edge devices in Arista's SD-WAN deployments. The vulnerability carries a maximum CVSS score of 10.0, reflecting the complete system access it provides to attackers.[5]

Arista Networks also issued urgent patches for CVE-2026-93952, an improper input validation issue in its VeloCloud Orchestrator.

The Arista vulnerability, which affects on-premises deployments, allows remote attackers to access privileged internal functionality without any authentication. Like the F5 flaw, it was added to the KEV catalog immediately after the vendor confirmed active exploitation in the wild. Arista has directed administrators to apply the latest software updates to secure their orchestration environments.[5]

The remaining two vulnerabilities affect Check Point's Security Gateway and management servers. CVE-2026-93616 is a pre-authentication path traversal flaw in the Check Point Management web service, while CVE-2026-85102 involves improper certificate validation in the Security Gateway and Spark Firewall products. Both flaws allow attackers to bypass authentication and execute code remotely.[1][2]

Check Point noted that the management server vulnerability had been probed by attackers in targeted strikes as early as July 23, 2026. The vendor released initial patches for the gateway flaw on September 9, 2026, but the subsequent confirmation of active exploitation prompted CISA to elevate the flaws to the mandatory remediation list.[2][4]

Edge devices like VPN gateways and SD-WAN orchestrators remain primary targets for network infiltration.

The clustering of these disclosures underscores a persistent trend in 2026: edge devices remain the primary entry point for network breaches. According to threat intelligence firm Senserva, 11 vulnerabilities crossed from theoretical to confirmed exploited in the wild in the last seven days alone, heavily concentrated on network infrastructure. Because these appliances handle VPN connections and traffic routing, they cannot be taken offline easily, often leading to delayed patching cycles that attackers reliably exploit.[4][6]

Network defenders face a difficult logistical balancing act when securing these systems. "VPN gateways get configured once at rollout and never touched again, because patching means kicking remote staff offline," noted Michael Sacco, Head of Service Delivery at All IT Services. Organizations must now check their specific hardware versions against the vendor advisories immediately, apply the hotfixes, and review their system logs for indicators of compromise, as the vulnerabilities were weaponized well before the public patches became available.[1]

What to know

  • CISA added four actively exploited zero-day vulnerabilities to its KEV catalog on September 22, 2026.
  • The flaws affect edge devices from Check Point, Arista Networks, and F5.
  • Federal agencies must apply the vendor-supplied hotfixes by September 25, 2026.
  • F5's BIG-IP APM vulnerability carries a critical CVSS score of 9.8 out of 10.
  • Attackers probed the Check Point management server flaw as early as July 2026.

Where opinion splits

Federal Regulators

CISA prioritizes rapid, mandatory remediation to close the window of opportunity for attackers.

The Cybersecurity and Infrastructure Security Agency approaches edge device vulnerabilities with strict compliance timelines. By issuing Binding Operational Directive 26-04, the agency shifts the operational posture of federal networks from scheduled maintenance to emergency response. Regulators argue that because these devices sit directly on the public internet, any delay in applying vendor hotfixes leaves critical infrastructure exposed to automated scanning and immediate exploitation.

Enterprise IT Providers

Managed service providers highlight the operational friction of patching edge devices during business hours.

For managed IT providers and enterprise defenders, emergency patches introduce significant operational friction. Edge devices like VPN gateways and SD-WAN orchestrators handle continuous remote workforce connectivity. Applying a patch typically requires a system reboot, which severs active sessions and disrupts business operations. Consequently, IT teams must balance the immediate security mandate from CISA against the logistical challenge of coordinating unscheduled downtime across multiple branch offices.

Sources

Source coverage

6 outlets

3 viewpoints surfaced

Federal Regulators 40%Network Hardware Vendors 30%Enterprise Security Defenders 30%
  1. [1]All IT ServicesEnterprise Security Defenders

    CISA Confirms Active Exploitation of Check Point, F5 and Arista Gear

    Read on All IT Services
  2. [2]TheCyberThroneFederal Regulators

    CISA adds Five Vulnerabilities to Exploitable Catalog

    Read on TheCyberThrone
  3. [3]CSO OnlineNetwork Hardware Vendors

    F5 fixes actively exploited zero-day flaw in BIG-IP APM

    Read on CSO Online
  4. [4]Shattered.ioEnterprise Security Defenders

    F5 BIG-IP Zero-Day CVE-2026-94127 Hits CVSS 9.8 [2026]

    Read on Shattered.io
  5. [5]SecurityWeekNetwork Hardware Vendors

    Arista Patches Actively Exploited VeloCloud Orchestrator Zero-Day

    Read on SecurityWeek
  6. [6]SenservaFederal Regulators

    Newest CISA KEV addition: 2026-09-22

    Read on Senserva

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.