Check Point and F5 reported active exploitation of remote code execution flaws in security gateways and management systems. Prioritize available vendor remediation and restrict exposed management or VPN services. These products can provide attackers with code execution on high-value security infrastructure.
Evidence window
24 Sept 2026, 06:15–25 Sept 2026, 06:15
Morning brief published
25 Sept 2026, 06:16
Assessment
URGENT
Morning assessment
Overall threat level: Critical
High confidence
High confidence — Check Point security infrastructure needs immediate attention.Check Point reported active exploitation of CVE-2026-85102 and CVE-2026-93616; ENISA lists both as known exploited.
High confidence — Affected F5 BIG-IP APM deployments face active exploitation risk.CERT-FR says F5 reported active exploitation of CVE-2026-94127, and ENISA lists it as known exploited.
High confidence — The reporting supports urgent remediation, not confirmed customer compromise.The reports establish public exploitation but contain no customer-specific intrusion evidence.
Assessment confidenceVendor-attributed exploitation reports are reinforced by ENISA EU KEV entries for three affected CVEs.
Morning analysis
What the evidence means
01
Attacks and available exploit tools
CVE-2026-85102 affects Check Point Quantum Security Gateway VPN certificate handling. BleepingComputer reported Check Point confirmed active exploitation, and ENISA lists it as known exploited. An unauthenticated attacker could execute code during VPN negotiation.
CVE-2026-93616 lets an unauthenticated attacker upload and execute scripts through Check Point Management Server. CERT-FR reports Check Point considers it actively exploited; ENISA also lists it as known exploited. The vendor advises restricting administrative-interface access and provides an R82.20 fix.
CVE-2026-94127 affects BIG-IP APM only when it acts as an OAuth Authorization Server. CERT-FR reports F5 confirmed active exploitation. Malicious data-plane traffic can enable unauthenticated remote code execution; vendor hotfixes are available for listed releases.
02
Attacker behavior
BleepingComputer reported that Check Point observed exploitation attempts against Spark customers from September 12. The attempts used VPN and proxy infrastructure to conceal origin.
04
What defenders can look for
CERT-FR states that F5 and Check Point provide compromise indicators in their vendor advisories for CVE-2026-94127 and CVE-2026-93616.
Further exploitation attempts against exposed Check Point and eligible F5 services are likely over the next 24–72 hours. Public reporting does not establish customer compromise.
New warning signs
Check Point reported a wave of CVE-2026-85102 exploitation attempts against Spark customers. This shows activity moved from an expected threat to reported exploitation.
Important changes since the last review
Check Point confirmed active exploitation of CVE-2026-85102 in Security Gateway VPN certificate handling.
CERT-FR reported F5-confirmed active exploitation of CVE-2026-94127 in eligible BIG-IP APM deployments.
CERT-FR reported Check Point-confirmed active exploitation of CVE-2026-93616 on Management Server.
Recommended actions
Actions supported by this assessment
If you operate Check Point Security Gateways, apply the vendor update for CVE-2026-85102 and investigate exposed VPN services for vendor-documented compromise indicators.
If you operate Check Point Management Server or Multi-Domain Security Management, restrict administrative-interface access, apply R82.20, and check the vendor indicators for CVE-2026-93616.
If you operate BIG-IP APM as an OAuth Authorization Server, apply F5's listed hotfix and investigate using the vendor compromise indicators for CVE-2026-94127.
CISA KEV added CVE-2026-71362, which BleepingComputer reports is leveraged in attacks. If you use Adobe Commerce or Magento, apply the recommended update or mitigation urgently.
Rapid7 published new research on CVE-2026-85706 today. The flaw can allow unauthenticated arbitrary file reads through GitLab's repository commits API. If you operate affected self-managed GitLab, upgrade to a fixed release immediately.
SecurityWeek reported exploitation of CVE-2026-48842. The flaw permits pre-authentication SQL injection through the virtuser_query plugin. If you use affected Roundcube versions, update to 1.6.16 or 1.7.1 promptly.
Rule-based activity matching: 0. 0 groups of sensor activity gained possible CVE matches from rules; 688 had no possible CVE match.
Potential network detection gaps: 104. 104 CVEs with public exploitation evidence may leave network indicators, but VTP lacks a reviewed, active detection rule. This is a detection-readiness estimate, not observed exploitation. For 1020 remote CVEs, VTP has not determined whether network traffic can identify them. Another 9 cannot be reliably identified from network traffic alone. 0 new public reports remain unresolved.
Reports on the threats discussed
Relevant reports supplied with the morning assessment. Publication dates distinguish earlier context from new reporting.
Greenbone Community Feed added exploit-oriented tooling coverage for CVE-2017-0144 and CVE-2017-0148. These flaws affect SMBv1 servers on listed legacy Windows versions and can permit remote code execution through crafted packets. ENISA lists CVE-2017-0144 as known exploited. If you operate affected SMBv1 systems, identify them, limit SMB reachability, and prioritize supported remediation or isolation.