The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

On September 22, 2026, CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after detecting active exploitation in the wild. The vulnerabilities span Check Point security appliances (CVE-2026-85102, CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), and F5 BIG-IP APM systems (CVE-2026-94127), affecting certificate validation, path traversal, input validation, and buffer overflow protections. These flaws enable attackers to achieve remote code execution and gain total system control on publicly exposed enterprise infrastructure. The addition coincides with the enforcement of Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize rapid remediation of KEV-listed vulnerabilities on internet-facing assets while establishing new requirements for compromise assessments prior to patching.

Why This Matters Now

These vulnerabilities represent active threat vectors being exploited against critical network infrastructure, with BOD 26-04 now requiring immediate federal agency response and establishing new precedents for risk-based vulnerability management across all sectors.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Four vulnerabilities were added: CVE-2026-85102 and CVE-2026-93616 affecting Check Point products, CVE-2026-93952 in Arista VeloCloud Orchestrator, and CVE-2026-94127 in F5 BIG-IP APM systems.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the blast radius of this multi-vector attack by constraining lateral movement through segmented east-west traffic flows and limiting uncontrolled egress paths used for data exfiltration.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial compromise of network appliances would likely still occur, but the scope of accessible cloud workloads and internal resources would be constrained through identity-aware routing and segmented access policies.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Administrative privilege escalation may still succeed on individual compromised systems, but the scope of elevated access would likely be constrained to specific network segments rather than spanning entire infrastructure domains.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement between network segments would likely be significantly constrained, reducing attacker reachability to cloud environments and internal systems through enforced traffic inspection and segmentation policies.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Command and control channels may still be established on initially compromised systems, but visibility into cross-cloud traffic patterns would likely enable detection and containment of unauthorized communication flows.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts would likely be constrained through controlled egress policies, reducing the volume and scope of data that could be transferred to unauthorized external destinations.

Impact (Mitigations)

While initial network infrastructure compromise may persist, the overall impact would likely be reduced through constrained lateral reach, limited data access scope, and reduced blast radius across cloud environments and internal systems.

Impact at a Glance

Affected Business Functions

  • Network Security Operations
  • Enterprise Infrastructure Management
  • Application Delivery Services
  • Network Access Control
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of network traffic, authentication credentials, and administrative access to enterprise infrastructure through exploitation of network security appliances and application delivery controllers.

Recommended Actions

  • • Implement inline IPS with Suricata signatures to detect and block known exploit patterns targeting CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, and CVE-2026-94127
  • • Deploy zero trust segmentation with identity-based policies to prevent lateral movement from compromised network appliances to cloud environments
  • • Enable encrypted traffic inspection using HPE capabilities to detect data exfiltration through unencrypted channels
  • • Establish egress security controls with FQDN filtering to prevent unauthorized data transfer to external destinations
  • • Implement multicloud visibility and control plane monitoring to detect anomalous interactions and suspicious automation across hybrid environments

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image