Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-23 · updated: 2026-09-23 · tags: [incident, government] · confidence: high · severity: medium · affected_sectors: [government] · au_impact: true

CISA added four vulnerabilities to the Known Exploited Vulnerabilities catalog on 22 September on evidence of active exploitation: CVE-2026-85102 (Check Point Multiple Products improper certificate validation), CVE-2026-93616 (Check Point path traversal), CVE-2026-93952 (Arista VeloCloud Orchestrator improper input validation) and CVE-2026-94127 (F5 BIG-IP APM heap-based buffer overflow). The F5 entry is the one without a matching news cycle behind it and deserves separate attention from administrators of the access policy manager, since BIG-IP APM is the component that brokers remote access into corporate applications. The additions land under Binding Operational Directive 26-04, CISA's risk-based vulnerability management directive, which requires federal civilian agencies to prioritise rapid remediation of KEV entries on publicly exposed assets that grant total control after exploitation, and which sets an expectation that agencies check for pre-compromise rather than simply patching. CISA notes the directive binds only federal civilian agencies but encourages all organisations to adopt the same prioritisation. The cadence is the point worth noting: this is the third KEV tranche in a week, following the 18 September Linux kernel additions and the 21 September Zyxel switch entry.

Attribute Detail
Sector Government
Date 2026-09-23
Source CISA
Reliability Tier 1
CVEs CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127