The US Cybersecurity and Infrastructure Security Agency added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog across two updates this week, on 22 and 24 September. Four of the six sit in network edge and management infrastructure: Check Point VPN gateways and management servers, F5 BIG-IP Access Policy Manager, and on-premises Arista VeloCloud Orchestrator. The other two affect WSO2’s API management stack and Adobe Commerce/Magento storefronts.
A KEV listing means CISA holds evidence that attackers are using the flaw in real intrusions. For the first four entries, the federal remediation deadline is today, 25 September, which says as much about how CISA rates the urgency as any severity score does.
What CISA has confirmed
Every one of the six entries carries the same core facts in the catalog: exploitation has been observed, whether any ransomware operation has used the flaw is recorded as unknown, and CISA has marked each one for forensic triage. That last flag matters. The catalog’s required action asks agencies not only to patch or mitigate under Binding Operational Directive 26-04, but also to follow CISA’s forensic triage requirements, meaning an exposed device should be checked for signs of prior compromise rather than simply updated and returned to service.
The additions, ordered by what we judge defenders should tackle first:
| CVE | Product | Weakness (per CISA) | Added | Federal due date |
|---|---|---|---|---|
| CVE-2026-85102 | Check Point Security Gateway, Spark Firewall (site-to-site and remote access VPN) | Improper certificate validation | 22 Sep | 25 Sep |
| CVE-2026-94127 | F5 BIG-IP APM | Heap-based buffer overflow | 22 Sep | 25 Sep |
| CVE-2026-93616 | Check Point Security Management, Multi-Domain, Log Server, SmartEvent | Path traversal | 22 Sep | 25 Sep |
| CVE-2026-93952 | Arista VeloCloud Orchestrator (on-prem) | Improper input validation | 22 Sep | 25 Sep |
| CVE-2026-5430 | WSO2 API Control Plane, API Manager, Traffic Manager, Universal Gateway | Path traversal | 24 Sep | 27 Sep |
| CVE-2026-71362 | Adobe Commerce and Magento | Incorrect authorization | 24 Sep | 27 Sep |
Why the edge devices come first
The Check Point gateway flaw and the F5 overflow share the worst profile on this list. According to CISA’s catalog entries, both can be triggered by an attacker who holds no credentials, and both can end in code running on the device itself. For Check Point, the exposure is any Security Gateway or Spark Firewall that terminates site-to-site or remote-access VPN, the part of a firewall that is internet-facing by design. For F5, the condition is narrower: the flaw is reachable only on a BIG-IP APM virtual server that has both an access policy and an OAuth profile configured. Teams running APM without OAuth are outside the described attack surface, but should confirm that from configuration rather than assume it.
The second Check Point entry targets the management tier rather than the gateway. CISA describes a path traversal in the Security Management Server and related log and event servers that lets an unauthenticated attacker place a script on the server and run it. A compromised management server controls policy for every gateway it manages, so this is arguably the more damaging of the pair even though management interfaces should rarely be reachable from the internet. If yours is, treat that as the first finding.
The VeloCloud entry applies only to on-premises Orchestrator deployments. CISA’s summary says a remote attacker could reach privileged internal functions and affect the orchestrator host, putting at risk both the Orchestrator and the SD-WAN configuration it holds for branch sites.
The application-layer pair
The WSO2 flaw is a path traversal that, per CISA, can be used to upload files without restriction and escalate to remote code execution across four API management products. Organisations using WSO2 as a public API gateway should assume the component is internet-facing.
The Adobe Commerce and Magento flaw is an authorization failure that CISA says can give an attacker elevated access to sensitive resources with no user interaction. For online retailers, sensitive resources on a storefront platform can include customer and order records.
What is not yet known
None of the six entries identifies a threat actor, a campaign, or the sectors being targeted, and CISA’s alerts do not say how widely each flaw is being exploited. Ransomware use is marked unknown for all six, which is different from “not used”. No indicators of compromise were published alongside these additions. We have not independently confirmed exploitation; the exploitation status reported here is CISA’s.
What to do now
- Inventory first. Identify every Check Point gateway running VPN, every Check Point management or log server, every BIG-IP APM virtual server with an OAuth profile, and any on-prem VeloCloud Orchestrator. Exposure on the public internet raises each one to the top of the queue.
- Patch or mitigate the edge devices today. Apply the vendor fixes linked from each KEV entry. For F5, the catalog notes a vendor-supplied iRule as an interim mitigation that preserves the device for forensic review; install the full patch once that review is done.
- Look for compromise, not just missing patches. CISA’s forensic triage flag on every entry is a strong hint that patched devices may already have been accessed. Review device logs, configuration changes, new local accounts, and unexpected files on management servers, and compare against a known-good baseline.
- Restrict management planes. Check Point management servers and VeloCloud Orchestrator should not accept connections from the open internet. Limit access to administrative networks while patching.
- Schedule WSO2 and Adobe Commerce by 27 September. Apply the vendors’ fixes, then check WSO2 gateway hosts for files you did not deploy and review Adobe Commerce admin accounts, roles and recent configuration changes for anything unexpected.
Organisations outside the US federal government are not bound by these deadlines, but the KEV catalog is one of the few public signals that separates exploited flaws from theoretical ones. Six confirmed-exploited entries in one week, four of them on perimeter equipment, is reason to move these ahead of routine patch cycles.
Source: Cybersecurity and Infrastructure Security Agency (CISA)