Skip to content
Critical Zero-Day Exploits Target F5 and Check Point Products

Critical Zero-Day Exploits Target F5 and Check Point Products

First seen 26 Sep 2026, 16:22 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 16:34 UTC
  • •F5's CVE-2026-94127 and Check Point's CVEs are actively exploited zero-days with CVSS scores of 9.8.
  • •CISA has added these vulnerabilities to its KEV catalog, highlighting their critical nature.
  • •Affected systems include F5 BIG-IP and Check Point Security Gateways, requiring urgent patching.

F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed two vulnerabilities, CVE-2026-85102 and CVE-2026-93616, both rated 9.8, with confirmed exploitation starting shortly after their respective patches were released. CVE-2026-85102 affects VPN gateways and exploits improper certificate handling, while CVE-2026-93616 allows RCE via path traversal in the Security Management web service. CISA added all three vulnerabilities to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch by September 25, 2026. The vulnerabilities are particularly concerning as they affect critical edge devices, increasing the risk of credential theft and lateral movement within networks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-09
CVE-2026-85102 published
Check Point disclosed a critical RCE vulnerability in its VPN gateways.
Pasqualepillitteri.It
2026-09-22
CVE-2026-94127 published
F5 released an emergency hotfix for a critical zero-day in BIG-IP Access Policy Manager.
Shattered
2026-09-22
CISA adds CVEs to KEV
CISA added CVE-2026-94127, CVE-2026-85102, and CVE-2026-93616 to its Known Exploited Vulnerabilities catalog.
Shattered
2026-09-22
CVE-2026-93616 published
Check Point disclosed a critical RCE vulnerability in its Security Management web service.
csirt.regione.toscana.it
2026-09-22
CVE-2026-93952 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-25
CISA patch deadline
CISA set a deadline for federal agencies to patch or take vulnerable devices offline.
Shattered

More articles in this cluster (7)

Following this threat?

Track CVE-2026-85102 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed