Overview

Daily vulnerability intelligence brief

2026-09-25

Check Point and F5 reported active exploitation of remote code execution flaws in security gateways and management systems. Prioritize available vendor remediation and restrict exposed management or VPN services. These products can provide attackers with code execution on high-value security infrastructure.

Evidence window
24 Sept 2026, 06:15–25 Sept 2026, 06:15
Morning brief published
25 Sept 2026, 06:16
Assessment
URGENT

Morning assessment

Overall threat level: Critical

High confidence
  1. High confidence — Check Point security infrastructure needs immediate attention.Check Point reported active exploitation of CVE-2026-85102 and CVE-2026-93616; ENISA lists both as known exploited.
  2. High confidence — Affected F5 BIG-IP APM deployments face active exploitation risk.CERT-FR says F5 reported active exploitation of CVE-2026-94127, and ENISA lists it as known exploited.
  3. High confidence — The reporting supports urgent remediation, not confirmed customer compromise.The reports establish public exploitation but contain no customer-specific intrusion evidence.
Assessment confidenceVendor-attributed exploitation reports are reinforced by ENISA EU KEV entries for three affected CVEs.

Morning analysis

What the evidence means

01

Attacks and available exploit tools

CVE-2026-85102 affects Check Point Quantum Security Gateway VPN certificate handling. BleepingComputer reported Check Point confirmed active exploitation, and ENISA lists it as known exploited. An unauthenticated attacker could execute code during VPN negotiation. CVE-2026-93616 lets an unauthenticated attacker upload and execute scripts through Check Point Management Server. CERT-FR reports Check Point considers it actively exploited; ENISA also lists it as known exploited. The vendor advises restricting administrative-interface access and provides an R82.20 fix. CVE-2026-94127 affects BIG-IP APM only when it acts as an OAuth Authorization Server. CERT-FR reports F5 confirmed active exploitation. Malicious data-plane traffic can enable unauthenticated remote code execution; vendor hotfixes are available for listed releases.

02

Attacker behavior

BleepingComputer reported that Check Point observed exploitation attempts against Spark customers from September 12. The attempts used VPN and proxy infrastructure to conceal origin.

04

What defenders can look for

CERT-FR states that F5 and Check Point provide compromise indicators in their vendor advisories for CVE-2026-94127 and CVE-2026-93616.

New during this period

Today's observations

03

No new finding became available for public display. This does not mean no sensor activity occurred.

What to watch next

Further exploitation attempts against exposed Check Point and eligible F5 services are likely over the next 24–72 hours. Public reporting does not establish customer compromise.

New warning signs

  • Check Point reported a wave of CVE-2026-85102 exploitation attempts against Spark customers. This shows activity moved from an expected threat to reported exploitation.

Important changes since the last review

  • Check Point confirmed active exploitation of CVE-2026-85102 in Security Gateway VPN certificate handling.
  • CERT-FR reported F5-confirmed active exploitation of CVE-2026-94127 in eligible BIG-IP APM deployments.
  • CERT-FR reported Check Point-confirmed active exploitation of CVE-2026-93616 on Management Server.

Recommended actions

Actions supported by this assessment

  1. If you operate Check Point Security Gateways, apply the vendor update for CVE-2026-85102 and investigate exposed VPN services for vendor-documented compromise indicators.
  2. If you operate Check Point Management Server or Multi-Domain Security Management, restrict administrative-interface access, apply R82.20, and check the vendor indicators for CVE-2026-93616.
  3. If you operate BIG-IP APM as an OAuth Authorization Server, apply F5's listed hotfix and investigate using the vendor compromise indicators for CVE-2026-94127.

Updates since the morning brief

Latest first · Times in Paris

3 updates
  1. Reported Roundcube exploitation requires prompt patching

    SecurityWeek reported exploitation of CVE-2026-48842. The flaw permits pre-authentication SQL injection through the virtuser_query plugin. If you use affected Roundcube versions, update to 1.6.16 or 1.7.1 promptly.

    View source

Last checked at 22:05.

Detection processing details

Rule-based activity matching: 0. 0 groups of sensor activity gained possible CVE matches from rules; 688 had no possible CVE match.

Potential network detection gaps: 104. 104 CVEs with public exploitation evidence may leave network indicators, but VTP lacks a reviewed, active detection rule. This is a detection-readiness estimate, not observed exploitation. For 1020 remote CVEs, VTP has not determined whether network traffic can identify them. Another 9 cannot be reliably identified from network traffic alone. 0 new public reports remain unresolved.

Reports on the threats discussed

Relevant reports supplied with the morning assessment. Publication dates distinguish earlier context from new reporting.

Earlier assessment

Earlier assessment still relevant

Assessed on 25 Sept 2026, 06:06
Review in your environment

Greenbone Community Feed added exploit-oriented tooling coverage for CVE-2017-0144 and CVE-2017-0148. These flaws affect SMBv1 servers on listed legacy Windows versions and can permit remote code execution through crafted packets. ENISA lists CVE-2017-0144 as known exploited. If you operate affected SMBv1 systems, identify them, limit SMB reachability, and prioritize supported remediation or isolation.

This earlier assessment still applies.

How this brief was prepared
Input size31,149 of 32,768 bytes
Filtered evidenceSelected public excerpts; no raw sensor payloads
AI rolegpt-5.6-terra · medium reasoning · counts come from VTP records