September 23, 2026

Command View


Verification cutoff

September 23, 2026, 14:38:34 UTC. This edition concentrates on four vulnerabilities added to CISA's Known Exploited Vulnerabilities (KEV) catalog on September 22. All four affect security gateways or the systems that administer network access and managed devices. The Siemens industrial advisory republished September 22 is identified by its original September 8 date.

Priority posture

  • RED: Check Point Security Management CVE-2026-93616, Check Point Security Gateway/Spark CVE-2026-85102, Arista VeloCloud Orchestrator CVE-2026-93952, and F5 BIG-IP APM CVE-2026-94127 have vendor-reported exploitation or attempted exploitation and were added to KEV. Exposed installations require immediate containment, remediation, and compromise assessment.
  • AMBER: Siemens Siveillance Control/Control Pro CVE-2026-50093 can give an attacker with the specified adjacent-network access and low privileges root-level access to the Open Interface Services host. No exploitation claim was established in the reviewed vendor advisory.
  • WATCH: Remaining VeloCloud Orchestrator release trains await confirmed fixed releases; operators must watch Arista's advisory and obtain branch-specific support guidance.
  • CONTEXT: A KEV listing establishes real-world exploitation of a vulnerability, not compromise of every exposed deployment. Observed probing of Check Point Spark systems must likewise be distinguished from confirmed successful intrusion.

Today's decisions

  • RED — Network-security owner: Inventory Check Point management servers and VPN-enabled gateways/Spark firewalls; deploy the applicable vendor fixes, then investigate pre-fix activity. Do not count LivePatch Take 28/29 as a fix for the management flaw.
  • RED — SD-WAN owner and incident response: Restrict VeloCloud Orchestrator web access, hunt for the vendor's host and network indicators, update supported 5.2.3 and 6.4.2 trains, and work with Arista on the remaining trains.
  • RED — Application-access owner: Identify BIG-IP virtual servers combining an APM access policy with an OAuth profile; install the matching engineering hotfix, or obtain F5's interim iRule; preserve logs and assess compromise.
  • AMBER — Physical-security/OT owner: Inventory Siemens Siveillance OIS deployments and plan the applicable fixed build without treating CISA's September 22 republication as a new discovery.

Threat and Resilience Ledger


[RED] — Security management | Global product exposure — Check Point management path traversal exploited before disclosure

Check Point reported on September 22 that CVE-2026-93616, a pre-authentication path traversal in the Security Management web service, permits arbitrary-path script execution and Java class loading. It reported a handful of pinpointed attacks on July 23, before the September 22 fix and disclosure; zero-day is justified for this flaw. The affected scope includes R82.20; R82.10 Jumbo Hotfix Take 44 or lower; R82 Take 126 or lower; R81.20 Take 166 or lower; R81.10 Take 190 or lower; and listed end-of-support releases. The vendor says LivePatch Take 28/29 does not fix it. Because a compromised management server can affect administered security policy and trust, restrict access, obtain the exact branch-specific fix from sk1000171, preserve logs, and validate administrator activity and managed gateways before declaring recovery. CISA added the CVE to KEV on September 22.
Evidence: confirmed vendor report of limited exploitation.
Attribution: unknown.
Confidence: high.
Uncertainty: the extent of successful intrusion, persistence, and downstream policy changes has not been published.
Sources: Check Point — “Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616,” September 22; Canadian Centre for Cyber Security — “Check Point security advisory (AV26-902) – Update 2,” September 22.

[RED] — VPN edge | Global product exposure — Check Point gateway flaw now targeted after its patch

The same September 22 Check Point advisory reports exploitation attempts against Spark customers beginning September 12 for CVE-2026-85102, an unauthenticated remote-code-execution flaw in VPN certificate handling. The company had disclosed and fixed it on September 9, so the observed campaign does not establish pre-disclosure exploitation. Security Gateway and centrally or locally managed Spark Firewall releases in the vendor's affected R81/R82 families require branch-appropriate fixes under sk1000117; VPN exposure and deployment configuration must be checked against that advisory. Hunt for anomalous certificate-based Mobile Access logins and subsequent internal scanning; the three certificate subjects Check Point published are examples, not an exhaustive indicator set. CISA added this CVE to KEV September 22.
Evidence: confirmed vendor report of exploitation attempts and KEV listing; success at an individual site requires investigation.
Attribution: unknown.
Confidence: high.
Uncertainty: the public account does not quantify successful compromises.
Sources: Check Point — “Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616,” September 22; Canadian Centre for Cyber Security — “Check Point security advisory (AV26-902) – Update 2,” September 22.

[RED] — SD-WAN orchestration | Global product exposure — VeloCloud host and managed-device trust at risk

Arista's September 22 Security Advisory 0183 says CVE-2026-93952 is actively exploited and can expose privileged VeloCloud Orchestrator (VCO) functionality and host data. On-premises VCO 5.2.x through 5.2.3.15, 6.1.x through 6.1.3.7, 6.4.x through 6.4.2.7, and 7.0.x through 7.0.0.2 are affected when certificate-based Edge-to-VCO authentication is configured, the attacker can obtain the public portion of an Edge authentication certificate, and the VCO web interface is reachable. Tenant or operator credentials are not required. Hosted and Dedicated instances were affected but, Arista says, have already been patched. Fixed on-premises releases include 5.2.3.16 and 6.4.2.8; other supported trains await published fixes. Restrict web access, preserve VCO logs, examine the vendor's named backdoor files and anomalous outbound traffic, and validate Edge configuration and credentials after a suspected compromise. CISA added the CVE to KEV on September 22.
Evidence: confirmed vendor report of active exploitation.
Attribution: unknown.
Confidence: high.
Uncertainty: affected organizations, attacker access to managed Edges, and release dates for other trains are undisclosed.
Sources: Arista — “Security Advisory 0183,” September 22; Canadian Centre for Cyber Security — “Arista Networks security advisory (AV26-947) – Update 1,” September 22.

[RED] — Application access edge | Global product exposure — F5 APM OAuth configuration exploited

F5's September 22 advisory, as corroborated by CERT-EU and the Canadian Cyber Centre, reports exploitation of CVE-2026-94127, a 9.8-rated heap-based buffer overflow permitting unauthenticated remote code execution in BIG-IP APM only where an APM access policy and an OAuth profile share a virtual server. Affected branches are 17.1.0–17.1.3, 17.5.0–17.5.1, and 21.1.0. Install the matching engineering hotfix: Hotfix-BIGIP-17.1.3.5.0.41.14-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, or Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, respectively. F5 Support can provide an interim iRule. Preserve /var/log/apm and /var/log/audit; repeated OAuth failures close in time to suspicious commands and TMM SIGABRT warrant human review, but any one signal alone does not prove compromise. The vulnerable path is in the data plane, although successful device compromise still calls for host-integrity review. CISA added the CVE to KEV September 22.
Evidence: confirmed vendor report of exploitation.
Attribution: unknown.
Confidence: high.
Uncertainty: victim count, attack chronology, and persistence details have not been released.
Sources: F5 — “K000162605: BIG-IP APM vulnerability CVE-2026-94127,” September 22; CERT-EU — “Security Advisory 2026-013: Critical Vulnerability in F5 BIG-IP APM,” September 22; Canadian Centre for Cyber Security — “Alert AL26-022,” September 22.

[AMBER] — Physical security integration | Global product exposure — Siemens OIS file upload can reach root

CISA republished Siemens' September 8 ProductCERT advisory on September 22; the underlying CVE-2026-50093 and fixes were not newly disclosed yesterday. The flaw affects the Open Interface Services (OIS) web module in Siveillance Control and Control Pro, systems used to integrate physical security operations at critical sites. Siemens assigns CVSS v3.1 9.0 with adjacent-network attack vector, low privileges, and additional attack requirements in CVSS v4; successful file upload may give root access to the OIS host. Fix Control V3.0 below 3.0.22.2177 or V4.0 below 4.0.11.2177, and Control Pro V3.0 below 3.0.12.2173 or V4.0 below 4.0.9.2178, at the respective stated releases or later. Restrict OIS access and test the update against site integrations.
Evidence: confirmed vulnerability and vendor fixes; no verified exploitation in the reviewed advisory.
Attribution: not applicable.
Confidence: high.
Uncertainty: installed exposure and any downstream physical-security effect at individual sites are unknown.
Sources: Siemens ProductCERT — “SSA-254516: Arbitrary File Upload in OIS Web Module,” September 8; CISA — “Siemens Siveillance Control,” ICSA-26-265-03, republished September 22.

Defensive Posture Changes


Assess trust after installing an edge fix

Collect the gateway and management logs before rotation or replacement. For Check Point, review certificate-based VPN access and management changes across the relevant exposure windows. For F5, correlate OAuth failures, audit actions, and TMM crashes; do not label a crash alone an intrusion. Fix deployment closes the vulnerability, but it does not undo earlier unauthorized changes.

Treat orchestration as a possible path into devices

Where VCO compromise is suspected, preserve the orchestrator's web, backend, system, and database evidence. Verify administrator actions, Edge state, certificates, and credentials; recover the orchestrator from a trusted source if investigation warrants it. Arista specifically warns that compromise may extend to managed Edge devices.

Keep OT remediation tied to access prerequisites

Prioritize Siemens OIS installations whose adjacent networks and low-privilege accounts could satisfy the vendor's attack conditions. Coordinate patch testing with physical-security owners so that door, alarm, and video integrations remain available; a theoretical effect on these integrations should not be described as a confirmed incident.

Regional and Sector Pulse


  • North America — RED: The Canadian Cyber Centre issued product-specific F5 guidance and updated its Check Point and VeloCloud advisories on September 22. Those notices establish regional defensive guidance, not confirmed Canadian victims.
  • Europe — RED: CERT-EU urged rapid F5 remediation and compromise assessment. Its notice does not establish a Europe-specific exploitation campaign.
  • Africa — WATCH: No Africa-specific victims or campaigns were verified in the reviewed advisories. Operators with the named edge or orchestration configurations have the same exposure-based response priority.
  • Middle East, Asia, Russia, China, and Indo-Pacific — WATCH: The vendor statements establish global product exposure; the reviewed sources do not support separate claims of activity in these regions. India is included in the Indo-Pacific category here.
  • Physical-security operators — AMBER: Siemens Siveillance OIS deployment at ports, airports, energy sites, and campuses makes the stated access prerequisites operationally relevant; no disruption at such sites is established.

Vulnerability and Supplier Watchlist


Check Point Security Management

Issue: CVE-2026-93616; pre-authentication path traversal, script execution and Java class load.
Affected scope: R82.20; R82.10 Jumbo Hotfix Take ≤44; R82 Take ≤126; R81.20 Take ≤166; R81.10 Take ≤190; older listed end-of-support releases.
Fixed release: vendor fix available September 22; exact build/take and validation instructions in sk1000171. LivePatch Take 28/29 is insufficient.
Severity: Check Point CVSS 9.8.
Status: RED — limited pre-disclosure exploitation reported; KEV listed.

Check Point Security Gateway / Spark Firewall

Issue: CVE-2026-85102; VPN certificate validation permits unauthenticated remote code execution.
Affected scope: vendor-listed R81/R82 Security Gateway and centrally or locally managed Spark releases; check VPN configuration and release against sk1000117.
Fixed release: vendor fixes available since September 9; obtain exact appliance/branch build from sk1000117.
Severity: Check Point CVSS 9.8.
Status: RED — exploitation attempts observed since September 12; KEV listed.

Arista VeloCloud Orchestrator

Issue: CVE-2026-93952; privileged internal access to VCO and possible host compromise.
Affected scope: on-premises 5.2.x ≤5.2.3.15; 6.1.x ≤6.1.3.7; 6.4.x ≤6.4.2.7; 7.0.x ≤7.0.0.2, with the specified Edge certificate and reachable web interface.
Fixed release: 5.2.3.16 and 6.4.2.8 for those trains; other train fixes not published by cutoff. Hosted/Dedicated already patched by Arista.
Severity: Arista CVSS v3.1 10.0; CVSS v4.0 9.5.
Status: RED — active exploitation confirmed by vendor; KEV listed.

F5 BIG-IP APM

Issue: CVE-2026-94127; unauthenticated remote code execution in configured OAuth authorization path.
Affected scope: 17.1.0–17.1.3, 17.5.0–17.5.1, 21.1.0 with APM access policy and OAuth profile on the same virtual server.
Fixed release: engineering hotfixes 17.1.3.5.0.41.14-ENG, 17.5.1.9.0.160.12-ENG, and 21.1.0.2.0.30.22-ENG respectively; interim iRule through F5 Support.
Severity: F5 CVSS v3.1 9.8.
Status: RED — exploited, KEV listed.

Siemens Siveillance Control / Control Pro OIS

Issue: CVE-2026-50093; arbitrary file upload with potential root access to OIS host.
Affected scope: Control V3.0 <3.0.22.2177; Control V4.0 <4.0.11.2177; Pro V3.0 <3.0.12.2173; Pro V4.0 <4.0.9.2178.
Fixed release: the four threshold releases above or later in the corresponding branch.
Severity: Siemens CVSS v3.1 9.0; adjacent-network, low-privilege prerequisites.
Status: AMBER — substantial OT-adjacent consequence, without verified exploitation in the reviewed advisory.

Outlook and Uncertainty


Next 24 hours

Watch for Arista fixed releases in the 6.1.x and 7.0.x trains; Check Point's branch-specific hotfix clarifications and hunting guidance; F5 detection and recovery detail; and confirmed post-exploitation evidence affecting managed devices or security policy. Recheck CISA's specific alert and KEV record if it is updated after this cutoff.

What is not known

The public advisories do not establish a complete victim count, persistence inventory, geographic distribution, or common actor across these four exploited vulnerabilities. The fact that an appliance has been patched or that no published indicator was found does not establish that its earlier state was trustworthy.

Trigger for escalation

For the AMBER Siemens item, a verified exploitation report or evidence of unauthorized OIS file upload would change its posture to RED. For the existing RED items, confirmed policy tampering, Edge takeover, broader intrusions, or new vendor recovery instructions would change the required containment and recovery scope.

© 2026 Border Cyber Group. All rights reserved.

Source Register


CISA KEV additions — four network access and management flaws

CISA — “CISA Adds Four Known Exploited Vulnerabilities to Catalog” — September 22, 2026:
https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog

CISA — Known Exploited Vulnerabilities machine-readable data (authoritative catalog record; consult dateAdded for each CVE):
https://github.com/cisagov/kev-data/blob/develop/known_exploited_vulnerabilities.json

Check Point Security Management and Security Gateway / Spark

Check Point — “Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616” — September 22, 2026:
https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/

Check Point — sk1000171, management CVE-2026-93616 fixes, hunting and validation:
https://support.checkpoint.com/results/sk/sk1000171

Check Point — sk1000117, gateway and Spark CVE-2026-85102 fixes:
https://support.checkpoint.com/results/sk/sk1000117

Canadian Centre for Cyber Security — “Check Point security advisory (AV26-902)” — updated September 22, 2026:
https://www.cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-902

Arista VeloCloud Orchestrator

Arista Networks — “Security Advisory 0183” — September 22, 2026:
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183

Canadian Centre for Cyber Security — “Arista Networks security advisory (AV26-947)” — updated September 22, 2026:
https://www.cyber.gc.ca/en/alerts-advisories/arista-networks-security-advisory-av26-947

F5 BIG-IP APM

F5 — “K000162605: BIG-IP APM vulnerability CVE-2026-94127” — published September 22, 2026:
https://my.f5.com/manage/s/article/K000162605

CERT-EU — “Critical Vulnerability in F5 BIG-IP APM,” Security Advisory 2026-013 — September 22, 2026:
https://cert.europa.eu/publications/security-advisories/2026-013/

Canadian Centre for Cyber Security — “Alert AL26-022: Vulnerability impacting F5 BIG-IP Access Policy Manager (APM), CVE-2026-94127” — September 22, 2026:
https://www.cyber.gc.ca/en/alerts-advisories/al26-022-vulnerability-impacting-f5-big-ip-access-policy-manager-apm-cve-2026-94127

Siemens Siveillance OIS

Siemens ProductCERT — “SSA-254516: Arbitrary File Upload in OIS Web Module” — September 8, 2026:
https://cert-portal.siemens.com/productcert/html/ssa-254516.html

CISA — “Siemens Siveillance Control,” ICSA-26-265-03 — September 22, 2026:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-03


This briefing is intended for defensive awareness and operational decision-making, not as a substitute for incident response, vendor guidance, or legal advice.

Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.

If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.

© 2026 Border Cyber Group. All rights reserved.


Jonathan Brown writes independent, decision-focused analysis on cybersecurity, infrastructure resilience, and operational risk, with an emphasis on primary-source verification and explicit uncertainty.

Support this work by sharing the briefing with operators who can act on it. Corrections supported by primary evidence are welcomed; material errors should be amended transparently. Feel free to subscribe, comment, or buy us a coffee! Thanks.

© 2026 Border Cyber Group. All rights reserved.