Thank you for reading or listening to The Realist Juggernaut. Independent journalism should be accessible to everyone.
THREAT SUMMARY
Category: Actively Exploited Vulnerabilities / Network Security / Security Appliances / Enterprise Infrastructure
Affected Product(s): Check Point multiple products, Arista VeloCloud Orchestrator, F5 BIG-IP APM
CVE(s): CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127
Primary Risks: Improper certificate validation, path traversal, improper input validation, heap-based buffer overflow, active exploitation of affected products
Threat Status: Active exploitation confirmed by CISA
Affected Environment(s): Federal Civilian Executive Branch environments and organizations operating affected Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM products
Attack Vector(s): Product-specific exploitation of the four vulnerabilities identified by CISA; the official alert does not provide additional exploitation mechanics
CISA Action: All four vulnerabilities added to the Known Exploited Vulnerabilities Catalog on September 22, 2026
Required Response: Federal Civilian Executive Branch agencies must follow applicable BOD 26-04 vulnerability-management requirements. CISA encourages all organizations to adopt risk-based vulnerability management and prioritize KEV Catalog vulnerabilities.
CISA has added four vulnerabilities affecting Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM to its Known Exploited Vulnerabilities Catalog after determining that all four are associated with active exploitation.
The September 22 additions are CVE-2026-85102, a Check Point improper certificate validation vulnerability; CVE-2026-93616, a Check Point path traversal vulnerability; CVE-2026-93952, an Arista VeloCloud Orchestrator improper input validation vulnerability; and CVE-2026-94127, an F5 BIG-IP APM heap-based buffer overflow vulnerability.
CISA states that vulnerabilities of these types are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
The importance of the alert is not based solely on the vulnerability classes.
CISA added the four CVEs to KEV because there is evidence of active exploitation.
That elevates them from ordinary vulnerability-management items to vulnerabilities requiring priority attention under CISA’s risk-based remediation framework.
Vulnerability Details
CVE-2026-85102 — Check Point Multiple Products Improper Certificate Validation Vulnerability
CISA identifies CVE-2026-85102 as an improper certificate validation vulnerability affecting multiple Check Point products.
The September 22 alert confirms active exploitation and places the flaw in the Known Exploited Vulnerabilities Catalog.
The official CISA material provided does not identify specific affected Check Point product versions, exploitation prerequisites, observed threat actors, indicators of compromise, or post-exploitation activity.
Organizations operating Check Point products should therefore use the KEV designation as the immediate prioritization signal and follow applicable remediation guidance associated with the vulnerability.
CVE-2026-93616 — Check Point Multiple Products Path Traversal Vulnerability
CISA identifies CVE-2026-93616 as a path traversal vulnerability affecting multiple Check Point products.
CISA has confirmed evidence of active exploitation and added the vulnerability to KEV.
The official alert does not provide additional technical details regarding the exploitation path, affected versions, attacker access requirements, or observed post-exploitation behavior.
Its inclusion in KEV establishes the central operational fact: this vulnerability is no longer being treated solely as a theoretical weakness.
CVE-2026-93952 — Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
CISA identifies CVE-2026-93952 as an improper input validation vulnerability affecting Arista VeloCloud Orchestrator.
The vulnerability was added to KEV based on evidence of active exploitation.
CISA’s September 22 alert does not specify affected versions, attack prerequisites, exploitation methodology, indicators of compromise, or the precise post-exploitation impact.
For defenders, the KEV designation establishes that the vulnerability should receive elevated remediation priority.
CVE-2026-94127 — F5 BIG-IP APM Heap-Based Buffer Overflow Vulnerability
CISA identifies CVE-2026-94127 as a heap-based buffer overflow vulnerability affecting F5 BIG-IP APM.
CISA has determined that the vulnerability is being actively exploited and added it to the KEV Catalog.
The official alert does not provide additional information concerning affected versions, exploitation conditions, remote or local access requirements, attacker behavior, or observed compromise patterns.
The confirmed fact is the active-exploitation status and corresponding KEV designation.
Affected Products
CISA’s September 22 alert identifies the affected products at the following level:
- Check Point multiple products — CVE-2026-85102.
- Check Point multiple products — CVE-2026-93616.
- Arista VeloCloud Orchestrator — CVE-2026-93952.
- F5 BIG-IP APM — CVE-2026-94127.
The alert does not provide version ranges or a complete affected-product matrix.
Organizations should not assume that every product from the named vendors is affected.
Administrators should use the CVE identifiers as the reference point when checking applicable remediation guidance and determining whether deployed systems are vulnerable.
Operational Impact
The immediate operational significance comes from CISA’s confirmation that all four vulnerabilities are being exploited.
That status changes remediation priority.
Security teams regularly manage large numbers of vulnerabilities across enterprise environments. KEV entries identify vulnerabilities for which CISA has evidence of active exploitation, giving organizations a direct signal for remediation prioritization.
CISA states that these types of weaknesses are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
For organizations running affected Check Point products, Arista VeloCloud Orchestrator, or F5 BIG-IP APM, the September 22 additions should trigger direct asset review and vulnerability prioritization.
The official alert does not establish whether exploitation is widespread, targeted, opportunistic, associated with any particular threat group, or concentrated in a specific sector.
Those conclusions should not be inferred from KEV inclusion alone.
What CISA has confirmed is that evidence of exploitation exists.
Federal Response
The four vulnerabilities fall under Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk.
BOD 26-04 establishes vulnerability-management requirements for Federal Civilian Executive Branch agencies and reinforces the importance of the Known Exploited Vulnerabilities Catalog in federal security operations.
Under the directive, federal agencies are required to prioritize rapid remediation of high-risk vulnerabilities, specifically KEV-listed CVEs affecting publicly exposed assets that grant total control of the asset after exploitation.
Lower-risk vulnerabilities may receive deferred action under the risk-based framework.
BOD 26-04 also establishes basic expectations for determining when agencies must check whether threat actors compromised a system before a patch was applied.
That requirement adds an important investigative component to vulnerability management.
Remediation does not always end with installation of a security update.
When applicable under BOD 26-04, agencies must also consider whether exploitation may have occurred before remediation was completed.
KEV
CISA’s Known Exploited Vulnerabilities Catalog is designed to identify vulnerabilities associated with real-world exploitation.
CISA states that potential KEV additions must meet three core conditions:
- A valid CVE identifier must exist.
- There must be evidence of exploitation.
- There must be clear mitigation guidance.
The four September 22 vulnerabilities met the requirements for inclusion.
CISA continues to add vulnerabilities to the catalog as they satisfy those criteria.
That process gives defenders a more focused method for vulnerability prioritization.
A vulnerability can exist in a product without being listed in KEV.
Once CISA confirms exploitation and adds the vulnerability to the catalog, organizations receive a stronger operational signal that remediation should move forward based on demonstrated attacker activity.
Defensive Guidance
Organizations using the affected products should determine whether the four CVEs apply to systems in their environments and review the applicable remediation guidance associated with each vulnerability.
Priority actions should include:
- Inventory Check Point products that may be associated with CVE-2026-85102 or CVE-2026-93616.
- Identify deployments of Arista VeloCloud Orchestrator associated with CVE-2026-93952.
- Identify F5 BIG-IP APM deployments associated with CVE-2026-94127.
- Confirm whether affected assets are publicly exposed.
- Review applicable remediation or mitigation guidance tied to each CVE.
- Prioritize KEV-listed vulnerabilities according to organizational risk.
- Apply required security updates or mitigations.
- Determine whether compromise assessment is required under applicable vulnerability-management procedures.
- Document remediation status across affected systems.
Federal Civilian Executive Branch agencies must follow the requirements established by BOD 26-04.
30-Day Outlook
The four September 22 additions warrant remediation priority because CISA added them to the KEV Catalog based on evidence of active exploitation.
Organizations should expect continued attention around KEV-listed vulnerabilities because publication in the catalog confirms that exploitation has already been observed.
The immediate defensive focus should remain on asset identification, exposure assessment, remediation, and any required compromise review.
CISA may continue adding vulnerabilities as new evidence of exploitation becomes available.
That creates an ongoing requirement for organizations to monitor KEV rather than treating vulnerability management as a static process.
For FCEB agencies, BOD 26-04 places additional emphasis on publicly exposed assets and high-risk KEV vulnerabilities capable of providing total control after exploitation.
That risk-based model will continue shaping federal remediation priorities.
TRJ Verdict
CISA’s September 22 alert puts four additional vulnerabilities into the category that defenders cannot treat as routine maintenance.
CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, and CVE-2026-94127 are now confirmed KEV entries based on evidence of active exploitation.
That is the central fact.
Two of the vulnerabilities affect Check Point products, one affects Arista VeloCloud Orchestrator, and one affects F5 BIG-IP APM.
The official alert does not provide deeper exploitation mechanics, affected-version matrices, attacker attribution, or indicators of compromise, so those details should not be assumed.
What CISA does provide is a clear remediation signal.
Federal Civilian Executive Branch agencies must apply the risk-based requirements of BOD 26-04, while CISA urges all organizations to prioritize KEV-listed vulnerabilities and adopt the same risk-focused vulnerability-management approach.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



