Machine-generated analysis · WAYSCloud LLM
Four CVEs affecting Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM have been added to the KEV catalog. The catalog addition signals active exploitation of these flaws.
Context
The advisory lists CVE-2026-85102 and CVE-2026-93616 affecting multiple Check Point products, CVE-2026-93952 affecting Arista VeloCloud Orchestrator, and CVE-2026-94127 affecting F5 BIG-IP APM. CISA added these vulnerabilities to its Known Exploited Vulnerabilities catalog because evidence shows they are being actively exploited. BOD 26-04 requires federal agencies to prioritize rapid remediation of such KEV items on publicly exposed assets.
Operator considerations
Check: inventory any deployments of the listed Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM versions vulnerable to the CVEs.
Isolate: limit external access to these assets until patches are applied.
Patch: apply vendor-provided fixes for the four CVEs as soon as they are available, per BOD 26-04.
Log: monitor for exploitation attempts related to these CVEs.
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability
CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability
CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize ra...
Read the full advisory on CISA →