Pasqualepillitteri.It Critical Zero-Day Exploits Target F5 and Check Point Products
Article Content
- •F5's CVE-2026-94127 and Check Point's CVEs are actively exploited zero-days with CVSS scores of 9.8.
- •CISA has added these vulnerabilities to its KEV catalog, highlighting their critical nature.
- •Affected systems include F5 BIG-IP and Check Point Security Gateways, requiring urgent patching.
F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed two vulnerabilities, CVE-2026-85102 and CVE-2026-93616, both rated 9.8, with confirmed exploitation starting shortly after their respective patches were released. CVE-2026-85102 affects VPN gateways and exploits improper certificate handling, while CVE-2026-93616 allows RCE via path traversal in the Security Management web service. CISA added all three vulnerabilities to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch by September 25, 2026. The vulnerabilities are particularly concerning as they affect critical edge devices, increasing the risk of credential theft and lateral movement within networks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track CVE-2026-85102 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical Citrix NetScaler Zero-Days Exploited Amid $387M Crypto Hack Citrix has confirmed that two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in its NetScaler ADC and Gateway products are being actively exploited. These vulnerabilities allow unauthenticated attackers to execute arbitrary commands and potentially disrupt services. CISA has added these flaws to…