Your Firewall Is the Breach: The Check Point and F5 Zero-Day Wave CISA Wants Closed by Tomorrow

Four edge-device flaws. All exploited. All reachable without a password.

CISA added them to the Known Exploited Vulnerabilities catalog on September 22 and gave federal agencies until September 25, a three-day window, to mitigate and complete forensic triage.

If you run Check Point gateways, Check Point management servers, F5 BIG-IP APM or on-prem Arista VeloCloud Orchestrator, this is your weekend.

Executive Summary

The devices you bought to keep attackers out are now the front door attackers are walking through.

In a single CISA update on September 22, four vulnerabilities in perimeter and perimeter-management products were confirmed as actively exploited: two in Check Point, one in F5 BIG-IP Access Policy Manager and one in Arista VeloCloud Orchestrator. Every one of them can be hit remotely by an unauthenticated attacker.

Two details should reset how your board thinks about patching. First, attackers began exploiting Check Point’s VPN certificate flaw about three days after the patch shipped. Second, a separate Check Point management-server flaw has been exploited since at least July 23, roughly two months before the emergency fix.

F5’s flaw landed as a true zero-day: exploited before the hotfix existed, rated CVSS 9.8, and sitting inside the component many enterprises use to hand out OAuth tokens to their applications.

The executive question is no longer “are we patched?” It is “were we already in someone else’s hands before we patched?”

Why This Matters to CISOs and Security Leaders

Edge devices are the most trusted and least watched systems in most enterprises. They sit on the internet. They terminate VPNs and authenticate users. They rarely run EDR. Their logs often go nowhere useful.

That combination makes them the ideal beachhead: one compromised gateway can hand an attacker valid sessions, credentials and a quiet path to internal scanning, without a single phishing email or malware alert on an endpoint.

A firewall compromise is not a network incident. It is an identity incident, a ransomware precursor and a disclosure question, all at once.
DataWater analysis

For leadership, three exposures converge here:

Operational. Emergency hotfixes on VPN and access gateways mean maintenance windows, possible remote-access disruption and fast change approvals.

Regulatory. If forensic triage finds pre-patch compromise, disclosure clocks (SEC materiality for US public companies, NIS2 and DORA reporting in Europe, sector regulators elsewhere) may start. Your counsel should be in the loop before the forensics come back, not after.

Insurance. A publicly listed, actively exploited KEV entry with a known fix is exactly the kind of item underwriters and claims adjusters ask about. Document when you learned, what you did and when you did it.

And that’s before you get to the most uncomfortable part of this week’s news.

The Biggest Cybersecurity Developments This Week

1. Check Point: VPN certificate flaw exploited globally (CVE-2026-85102)

A pre-authentication remote code execution bug in Check Point Quantum Security Gateway and Spark firewalls, triggered during VPN negotiation when an attacker presents a malicious certificate. Check Point patched it on September 9. By September 12, it was seeing exploitation attempts against Spark customers, originating from VPN services and proxies used to hide the attackers’ origin.

“We are now observing exploitation attempts against Check Point Spark customers globally.”
Lotem Finkelstein, VP of Research, Check Point (via Help Net Security)

Spark is aimed at small and mid-sized businesses and managed service providers. That matters for enterprises too: your MSPs, franchisees, branch offices and smaller suppliers are likely Spark users, and they are connected to you.

Reported affected Quantum Gateway builds include R82.10 with Jumbo Hotfix Take 43 or below, R82 with Take 125 or below, and R81.20 with Take 165 or below. The Dutch NCSC had warned in early September that exploitation was likely soon; a companion bug, CVE-2026-85103, was fixed in the same release but has not been reported as exploited.

2. Check Point: management servers exploited since July (CVE-2026-93616)

A pre-authentication path traversal in the Check Point Management web service, affecting Security Management Server, Multi-Domain Security Management, Log Server, Multi-Domain Log Server and SmartEvent. Check Point says exploitation goes back to at least July 23, 2026, and has released emergency hotfixes.

Management servers hold policy, logs and control over every gateway they manage. If you can’t patch immediately, restrict management access to trusted internal IP addresses now.

3. F5 BIG-IP APM: zero-day RCE in OAuth authorization servers (CVE-2026-94127)

A heap-based buffer overflow rated 9.8 (CVSS v3.1) and 9.3 (CVSS v4.0). It applies when APM acts as an OAuth authorization server, meaning an APM access policy and an OAuth authorization server profile sit on the same virtual server. Deployments that use APM only as an OAuth client or resource server are not affected. Appliance mode is not a shield.

Crucially, the malicious traffic goes to the virtual server itself, so locking down the BIG-IP management interface does not protect you. Shadowserver is tracking more than 14,700 IP addresses with BIG-IP APM fingerprints, with North America and Europe each accounting for roughly 5,000 (fingerprints, not a count of vulnerable systems).

4. Arista VeloCloud Orchestrator (CVE-2026-93952)

An input validation flaw in on-premises VeloCloud Orchestrator that may let a remote attacker reach privileged internal functionality. Hosted VCO environments have already been patched; on-prem operators need to update. The orchestrator controls your SD-WAN fabric, so treat it with the same priority as a firewall manager.

The same week, the pattern repeated elsewhere

Researchers reported that Chinese hackers are reverse-engineering Chrome fixes published in open source before those fixes reach users, exploiting the “patch gap.” Microsoft disrupted the EvilTokens phishing service, which had given criminals access to 12,000 inboxes. Different vendors, one lesson: disclosure is now the starting gun, not the finish line.

Threat Intelligence Breakdown

CVE Product Type Status Emergency move
CVE-2026-85102 Check Point Quantum Security Gateway, Spark Improper certificate validation, pre-auth RCE via VPN negotiation (CVSS 9.8) Exploited from Sept 12 Apply Sept 9 fixes; hunt anomalous certificate-based logins and internal scanning
CVE-2026-93616 Check Point Management, MDS, Log Server, SmartEvent Pre-auth path traversal Exploited since at least July 23 Emergency hotfix; restrict management access to trusted internal IPs
CVE-2026-94127 F5 BIG-IP APM (OAuth authorization server) Heap overflow, unauthenticated RCE (CVSS 9.8) Zero-day, exploited before fix Preserve evidence, apply F5 iRule, install engineering hotfix
CVE-2026-93952 Arista VeloCloud Orchestrator (on-prem) Improper input validation Exploited Update on-prem VCO; hosted already patched

What we know about the attackers

Public reporting so far describes infrastructure, not identity: the Check Point attempts came through anonymizing VPNs and proxies and used specific certificate subjects listed in Check Point’s advisory. No public attribution has been made for this wave. Treat anyone claiming a named actor right now with caution.

Context matters, though. Researchers earlier this month uncovered a Linux rootkit implant built specifically for BIG-IP APM systems, tied to exploitation of an older F5 vulnerability. Attackers are investing in persistence on edge appliances, which means patching alone may not evict someone who got in first.

What nobody is talking about

The CISA deadline covers mitigation and forensic triage. For F5, CISA told agencies to apply the iRule first so that triage can happen, then patch. That ordering is the tell: the government assumes some of these boxes were already compromised. Most enterprise change tickets say “patch.” Very few say “image, preserve logs, then patch.”

Vulnerability & Exploit Analysis

Check Point CVE-2026-85102 is exploitable over site-to-site and remote-access VPN connections. The attack happens at the certificate stage, before a user ever authenticates. That’s why it is so dangerous: there is no login to fail, and no MFA prompt to block.

F5 CVE-2026-94127 targets the OAuth path. F5’s indicators of compromise, echoed by CERT-EU, are a combination rather than any single signal:

  • Repeated OAuth authentication failures in /var/log/apm, especially many from one source IP
  • Suspicious command activity shortly afterward
  • A TMM SIGABRT crash in the same timeframe

Reported F5 hotfixes by branch: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG (21.x), Hotfix-BIGIP-17.5.1.9.0.160.12-ENG (17.5.x) and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG (17.1.x). The iRule mitigation is available by opening a ticket with F5 support. One trap: systems already updated to 17.1.3 or 17.5.1.3 for the earlier CVE-2025-53521 still need this new hotfix if APM is an OAuth authorization server.

The hidden enterprise risk

BIG-IP APM configured as an OAuth authorization server is often the thing issuing tokens for SSO and federated apps. Code execution there is not just a box compromise; it can put token issuance and session trust for downstream applications in question. Scope your investigation accordingly.

AI-Powered Cybersecurity Risks

There is no public evidence that AI was used in this specific exploitation wave. But the timeline tells you why AI matters here anyway.

Three days from patch to exploitation is consistent with patch diffing at speed: attackers compare the fixed and unfixed code, find the change, and weaponize it. That work is becoming faster and cheaper with AI-assisted reverse engineering, and the Chrome “patch gap” reporting this week shows attackers already industrializing it.

The implication is blunt: your patch SLA was designed for human-speed adversaries. If your edge devices sit on a 30-day cycle, you are measuring in months against an opponent measuring in days.

The defensive flip side is real too. The same AI tooling can help SOC teams triage appliance logs, correlate the F5 indicator chain across thousands of lines, and draft forensic timelines faster. The teams that move first on that will feel this week very differently.

Cloud & Infrastructure Security Impact

This is a hybrid-infrastructure story. Hosted VeloCloud instances were patched by the provider; on-prem instances were not. That split is the whole argument for knowing, precisely, which of your control-plane systems you operate yourself.

Edge devices also bridge on-prem and cloud. A compromised VPN gateway or OAuth server can yield sessions and tokens that reach SaaS and cloud workloads. The recent Klue breach is a reminder that OAuth grants are already a quiet back door in SaaS; an attacker sitting on your token issuer makes that back door wider.

OT and IoT teams should pay attention as well. Industrial sites often reach vendors and headquarters through exactly these gateways, and SecurityWeek reports only 21% of industrial security leaders have a complete OT asset inventory. You cannot patch a gateway you don’t know you own.

Ransomware & Nation-State Threats

Edge-device exploitation has, over the past several years, been a favored entry point for both state-backed espionage groups and ransomware affiliates. Espionage actors value persistence on trusted appliances; ransomware crews value the valid VPN sessions and credentials those appliances hold.

Nothing public ties this week’s wave to a specific group. But the operational playbook after an edge compromise is well understood: harvest credentials, scan internally, move to identity infrastructure, stage data, and in the ransomware case, encrypt. Check Point’s own guidance to monitor for unauthorized internal network scanning tells you which step defenders should be hunting for right now.

So who comes out of this week stronger, and who doesn’t?

Winners and Losers

Better positioned More exposed
Teams with a separate, faster patch SLA for internet-facing infrastructure Teams patching edge devices on the standard monthly cycle
Organizations shipping appliance logs to a SIEM and hunting them Organizations whose firewall and APM logs stay on the box
Management consoles reachable only from internal admin networks Management interfaces exposed to the internet
Security leaders with pre-approved emergency change and IR retainers Anyone negotiating change windows during an active KEV deadline
Enterprises that inventory third-party and MSP-managed edge devices Enterprises that assume supplier firewalls are the supplier’s problem

The broader market signal is the one boards will hear about: every wave like this strengthens the case for shrinking the internet-exposed appliance footprint in favor of identity-centric access models, and for continuous exposure management over periodic scanning. That’s a strategic direction, not an emergency fix. The emergency fix is below.

What Security Leaders Should Do Next

Next 24 hours

  1. Find every affected asset. Check Point gateways and Spark units (including MSP-managed and branch devices), Check Point management and log servers, BIG-IP APM with OAuth authorization server profiles, on-prem VeloCloud Orchestrator.
  2. Preserve evidence before changing anything. Snapshot configs and pull logs off the device. Patching and rebooting can destroy the volatile evidence you’ll need.
  3. Mitigate. Restrict Check Point management access to trusted internal IPs. Apply F5’s iRule where the hotfix can’t go in immediately.
  4. Patch. Check Point September 9 fixes and emergency management hotfixes; F5 engineering hotfixes per branch; VeloCloud on-prem updates.
  5. Hunt. Anomalous certificate-based VPN logins and the certificate subjects in Check Point’s advisory; F5’s OAuth-failure, command, SIGABRT chain; unexpected internal scanning from gateway addresses.

Next 30 days

  1. Create an edge-device patch SLA measured in days, with pre-approved emergency change.
  2. Get appliance logs into your SIEM and write detections for the indicator patterns above.
  3. If you find compromise, rotate what the device touched: VPN and admin credentials, certificates, OAuth signing material and sessions issued by affected systems.
  4. Brief counsel and your insurer on timeline and findings so disclosure decisions are made deliberately.
  5. Ask your MSPs and critical suppliers in writing whether they run these products and when they patched.

Share this with your infrastructure and SOC leads today

The federal deadline is September 25. Attackers aren’t waiting for yours. Get DataWater’s executive threat briefings as they break.

Subscribe to DataWater briefings

The Future of Enterprise Cybersecurity

This week is a preview, not an outlier. The perimeter is being attacked at the exact layer defenders trusted most, on timelines that are compressing toward days.

Expect three shifts. Patch velocity becomes a board metric for internet-facing systems. Appliances get treated as identities, monitored and constrained like privileged accounts. And forensics-first response replaces patch-and-forget, because the question after every KEV listing will be whether someone got there first.

The organizations that adapt will treat CISA’s KEV catalog as their own deadline calendar. The ones that don’t will learn about their edge exposure from an incident responder.

Final Executive Takeaway

Patch today. Investigate as if you were already breached. Then fix the process that let a three-day exploit window meet a thirty-day patch cycle.

Your perimeter didn’t fail because it was weak. It failed because it was trusted and unwatched.

Frequently Asked Questions

What is CVE-2026-85102?

A critical pre-authentication remote code execution vulnerability in Check Point Quantum Security Gateway and Spark firewalls, triggered by a malicious certificate during VPN negotiation. Check Point patched it on September 9, 2026, and observed exploitation from September 12.

Which F5 BIG-IP systems are affected by CVE-2026-94127?

BIG-IP APM systems where APM acts as an OAuth authorization server, meaning an APM access policy and an OAuth authorization server profile are on the same virtual server. Systems using APM only as an OAuth client or resource server are not affected.

Does restricting the BIG-IP management interface stop CVE-2026-94127?

No. The malicious traffic targets the virtual server that handles OAuth requests, not the management interface. Apply F5’s hotfix or its iRule mitigation.

What is the CISA deadline for these vulnerabilities?

CISA added all four to its Known Exploited Vulnerabilities catalog on September 22, 2026, with a September 25, 2026 deadline for US federal civilian agencies. The deadline is not binding on private companies, but it is a strong signal of urgency.

How do I know if my F5 device was exploited?

Look for the combination F5 describes: repeated OAuth authentication failures in /var/log/apm, followed by suspicious commands, followed by a TMM SIGABRT crash. No single indicator is conclusive; preserve evidence and escalate to incident response if they line up.

Why are attackers targeting firewalls and VPN gateways?

They are internet-facing, highly trusted, often lack endpoint monitoring, and hold credentials and sessions that lead directly into the internal network.

Sources

Similar Posts