Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
CISA adds four actively exploited zero-days to KEV, forcing immediate patching of critical flaws in Check Point, Arista, and F5 systems.
CISA has added four actively exploited zero-day vulnerabilities to its KEV catalog, forcing US federal agencies to patch by September 25. The list includes critical flaws in Check Point Security Management (CVE-2026-93616) and Security Gateway (CVE-2026-85102), alongside zero-days in Arista VeloCloud Orchestrator (CVE-2026-93952) and F5 BIG-IP APM (CVE-2026-94127). Check Point confirmed exploitation against Management Servers and Spark firewalls globally.