This brief covers September 22–23, 2026. Every item below was checked against CISA’s KEV alert and the vendor advisory as reported. On September 22, CISA added four actively exploited flaws to the Known Exploited Vulnerabilities catalog. Three are zero-days in edge and management infrastructure: F5 BIG-IP APM, Arista VeloCloud Orchestrator, and Check Point Management Server. Federal agencies were given three days to patch under BOD 26-04.
F5 BIG-IP APM: unauthenticated RCE exploited as a zero-day (CVE-2026-94127)
F5 / CISA · September 22, 2026
CVE-2026-94127 (CVSS 9.8) is a heap-based buffer overflow in BIG-IP Access Policy Manager. An unauthenticated attacker can use it for remote code execution when an APM access policy and an OAuth profile are configured on a virtual server. Only deployments using APM as an OAuth Authorization Server are affected; Appliance mode is also vulnerable. Affected versions are 21.1.0, 17.5.0–17.5.1 and 17.1.0–17.1.3. F5 has shipped hotfixes and published three indicators of compromise (IoCs). The flaw is actively exploited and was added to KEV on September 22.
“We have learned that this vulnerability has been exploited.” — F5 advisory K000162605
Source: F5 K000162605 · SecurityWeek
Arista VeloCloud Orchestrator On-Prem: CVSS 10 zero-day under active attack (CVE-2026-93952)
Arista / CISA · September 22, 2026
CVE-2026-93952 (CVSS 10) is an improper input validation flaw in on-premises VeloCloud Orchestrator (VCO). It lets remote attackers reach privileged internal functionality without tenant or operator credentials. Only instances using certificate-based Edge-to-VCO authentication are exposed. The flaw is fixed in VCO 5.2.3.16 and 6.4.2.8, and patches for other trains are coming. Arista has published no definitive IoCs and recommends reviewing web, application and system logs. The flaw is actively exploited and was added to KEV on September 22.
“This issue was discovered externally and is known to be actively exploited.” — Arista Security Advisory 0183
Source: Arista Security Advisory 0183 · SecurityWeek
Check Point Management Server: pre-auth path traversal and file upload zero-day (CVE-2026-93616)
Check Point / CISA · September 22, 2026
CVE-2026-93616 (CVSS 9.8) is a directory traversal and file upload flaw. It lets unauthenticated attackers upload and run arbitrary scripts on Security Management Server, Multi-Domain Security Management, Log Server, Multi-Domain Log Server and SmartEvent. Fixes are in the R82.20 Security Hotfix and in Jumbo Hotfix Takes for R82.10, R82, R81.20 and R81.10. Standard LivePatch updates do not fix it. As interim mitigation, restrict TCP/19009 to trusted IPs. The flaw is actively exploited against a small number of customers and was added to KEV on September 22.
“This vulnerability is exploited in the Wild. Check Point is aware of a handful of customers who have been attacked.” — Check Point sk1000171
Source: Check Point sk1000171 · SecurityWeek
Check Point Security Gateway / Spark VPN auth bypass now exploited (CVE-2026-85102)
Check Point / CISA · September 22, 2026
CVE-2026-85102 (CVSS 9.8) is improper certificate validation during VPN negotiation. It allows unauthenticated authentication bypass and code execution on Security Gateway and Spark firewalls. Check Point patched it on September 9 and at that time had no evidence of exploitation. It now reports exploitation attempts against Spark customers worldwide. The flaw was added to KEV on September 22.
“We are now observing exploitation attempts against Check Point Spark customers globally.” — Check Point
Source: Check Point advisory blog · CISA KEV alert
Still developing
Zyxel GS1900 switch stack overflow added to KEV (CVE-2026-7273)
CISA · September 21, 2026
CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 Series switches, to the KEV catalog based on evidence of active exploitation. SecurityWeek has linked the exploitation to Chinese threat actors. GS1900 owners should apply Zyxel’s fixed firmware.
Source: CISA KEV alert
Brevo supply-chain attack served ClickFix malware through embedded scripts
Brevo / Sansec · September 18, 2026
Attackers used a compromised long-lived Cloudflare API key to deploy a worker. The worker injected malicious scripts into brevo.com, sibforms.com and three JavaScript files that customers embed on their sites. The scripts showed selected visitors fake “verify you are human” ClickFix pages. On WordPress sites where the visitor was a logged-in admin, they tried to install a plugin. Sansec estimates more than 100,000 sites were affected. Sites that embed Brevo widgets should check for unauthorized plugins.
Source: Brevo post-mortem · Sansec · SecurityWeek
This brief covers the trailing ~48 hours (September 22–23, 2026).
Primary sources: