Executive Summary
On September 22, 2026, CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after detecting active exploitation in the wild. The vulnerabilities span Check Point security appliances (CVE-2026-85102, CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), and F5 BIG-IP APM systems (CVE-2026-94127), affecting certificate validation, path traversal, input validation, and buffer overflow protections. These flaws enable attackers to achieve remote code execution and gain total system control on publicly exposed enterprise infrastructure. The addition coincides with the enforcement of Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize rapid remediation of KEV-listed vulnerabilities on internet-facing assets while establishing new requirements for compromise assessments prior to patching.
Why This Matters Now
These vulnerabilities represent active threat vectors being exploited against critical network infrastructure, with BOD 26-04 now requiring immediate federal agency response and establishing new precedents for risk-based vulnerability management across all sectors.
Attack Path Analysis
Attackers exploited known vulnerabilities in Check Point firewall products, Arista VeloCloud Orchestrator, and F5 BIG-IP APM systems to gain initial access to network infrastructure. They then escalated privileges using certificate validation bypasses and path traversal vulnerabilities to access administrative functions. Lateral movement occurred through compromised network appliances to reach cloud environments and internal systems. Command and control was established through encrypted channels bypassing traditional perimeter defenses. Data exfiltration proceeded through unmonitored east-west traffic and inadequately controlled egress points. Final impact included potential data theft and compromise of critical network security infrastructure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, and CVE-2026-94127 to compromise Check Point firewalls, Arista VeloCloud Orchestrator, and F5 BIG-IP APM systems through improper certificate validation, path traversal, input validation flaws, and buffer overflow vulnerabilities
Related CVEs
CVE-2026-85102
CVSS 9.8Improper certificate validation vulnerability in Check Point multiple products allows attackers to bypass SSL/TLS security controls.
Affected Products:
Check Point Multiple Products – Various versions
Exploit Status:
exploited in the wildCVE-2026-93616
CVSS 9.8Path traversal vulnerability in Check Point multiple products allows attackers to access files outside of restricted directories.
Affected Products:
Check Point Multiple Products – Various versions
Exploit Status:
exploited in the wildCVE-2026-93952
CVSS 10Improper input validation vulnerability in Arista VeloCloud Orchestrator allows remote code execution through malicious input.
Affected Products:
Arista Networks VeloCloud Orchestrator – Various versions
Exploit Status:
exploited in the wildCVE-2026-94127
CVSS 9.8Heap-based buffer overflow vulnerability in F5 BIG-IP APM allows remote attackers to execute arbitrary code.
Affected Products:
F5 Networks BIG-IP APM – Various versions
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Exploitation for Credential Access
Process Injection
Valid Accounts
Exploitation of Remote Services
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
PCI DSS 4.0 – External Penetration Testing
Control ID: 11.3.1
CISA Zero Trust Maturity Model 2.0 – Asset Management
Control ID: Networks Function NW.AM
DORA – Identification
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face critical vulnerability exploitation risks requiring rapid remediation under BOD 26-04, with network segmentation and encrypted traffic capabilities essential.
Financial Services
Banking institutions vulnerable to Check Point and F5 BIG-IP exploits threaten PCI compliance, requiring zero trust segmentation and egress security controls.
Health Care / Life Sciences
Healthcare networks exposed to path traversal and buffer overflow attacks risk HIPAA violations, demanding multicloud visibility and threat detection capabilities.
Telecommunications
Telecom infrastructure faces east-west traffic security risks from active CVE exploitation, requiring encrypted traffic solutions and anomaly detection systems.
Sources
- CISA Adds Four Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalogVerified
- Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- Binding Operational Directive 26-04https://www.cisa.gov/news-events/directives/binding-operational-directive-26-04Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this multi-vector attack by constraining lateral movement through segmented east-west traffic flows and limiting uncontrolled egress paths used for data exfiltration.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise of network appliances would likely still occur, but the scope of accessible cloud workloads and internal resources would be constrained through identity-aware routing and segmented access policies.
Control: Zero Trust Segmentation
Mitigation: Administrative privilege escalation may still succeed on individual compromised systems, but the scope of elevated access would likely be constrained to specific network segments rather than spanning entire infrastructure domains.
Control: East-West Traffic Security
Mitigation: Lateral movement between network segments would likely be significantly constrained, reducing attacker reachability to cloud environments and internal systems through enforced traffic inspection and segmentation policies.
Control: Multicloud Visibility & Control
Mitigation: Command and control channels may still be established on initially compromised systems, but visibility into cross-cloud traffic patterns would likely enable detection and containment of unauthorized communication flows.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be constrained through controlled egress policies, reducing the volume and scope of data that could be transferred to unauthorized external destinations.
While initial network infrastructure compromise may persist, the overall impact would likely be reduced through constrained lateral reach, limited data access scope, and reduced blast radius across cloud environments and internal systems.
Impact at a Glance
Affected Business Functions
- Network Security Operations
- Enterprise Infrastructure Management
- Application Delivery Services
- Network Access Control
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of network traffic, authentication credentials, and administrative access to enterprise infrastructure through exploitation of network security appliances and application delivery controllers.
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline IPS with Suricata signatures to detect and block known exploit patterns targeting CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, and CVE-2026-94127
- • Deploy zero trust segmentation with identity-based policies to prevent lateral movement from compromised network appliances to cloud environments
- • Enable encrypted traffic inspection using HPE capabilities to detect data exfiltration through unencrypted channels
- • Establish egress security controls with FQDN filtering to prevent unauthorized data transfer to external destinations
- • Implement multicloud visibility and control plane monitoring to detect anomalous interactions and suspicious automation across hybrid environments



