endoflife.ai
Check Point Gaia F5 BIG-IP VeloCloud (July) Exploited & Unpatchable

Three Vendors Shipped Emergency Fixes. All Stopped at End of Support.

By Scott Bissett  ·  Published: September 23, 2026  ·  Read at each vendor's own advisory and CISA's live catalog

On September 22, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog in a single batch and gave federal agencies until September 25, 2026 to fix them. Three vendors, four CVEs, one deadline. What makes the batch worth a page of its own is not the flaws. It is that all three vendors published advisories the same day, and every one of those advisories stops at the end-of-support line. If you run an end-of-support release of Check Point, BIG-IP or VeloCloud Orchestrator, the vendor's own document says, in its own words, that no fix is coming.

The deadline is Friday. Federal agencies must remediate all four by September 25, 2026 under CISA's BOD 26-04. For everyone else the date is a signal of how fast the exploitation is moving: all four entries were added with the standard three-day window CISA reserves for flaws under active attack.
Quick answer: BIG-IP 21.1 is supported until May 5, 2029, its end-of-support date. The next BIG-IP version to reach end of life is 17.1, on March 31, 2027. 28 of 31 tracked BIG-IP versions are past end of life; the most recent to reach it, 21.0, did so on August 6, 2026. Every BIG-IP version's release and end-of-support date is on the BIG-IP lifecycle page.

The four entries

CVEVendor and productCVSSAdded to KEVFederal due date
CVE-2026-93952Arista VeloCloud Orchestrator (on-prem)10.0September 22, 2026September 25, 2026
CVE-2026-94127F5 BIG-IP APM9.8September 22, 2026September 25, 2026
CVE-2026-93616Check Point Security Management9.8September 22, 2026September 25, 2026
CVE-2026-85102Check Point Security Gateway and Spark9.8September 22, 2026September 25, 2026

Source: CISA's Known Exploited Vulnerabilities catalog, read from the live JSON feed. Each vendor's advisory was then read in full; the quotations below are theirs.

Running Check Point past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers Check Point is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

Check Point: the unsupported releases are named, and marked EoS

Check Point's advisory covers two flaws. CVE-2026-85102 is a pre-authentication remote code execution vulnerability in the Security Gateway's VPN certificate handling. Check Point released fixes on September 9, 2026 with no evidence of exploitation at the time; starting September 12, 2026 it observed a wave of exploitation attempts against Spark customers. A supported customer had three days between fix and attack. CVE-2026-93616 is a zero-day in Security Management with a fix published the same day as the advisory.

The affected-versions tables do something most vendors avoid: they list the end-of-support releases as affected and label them. For CVE-2026-85102 the list reads R81 (EOS), R81.10 (EOS), then the supported R81.10.X, R81.20, R82, R82.00.X and R82.10. For CVE-2026-93616 the list ends with R81.10 Take 190 or lower (EoS) and R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS). Seven releases, affected, no fix. Check Point's own support life-cycle table puts R81.10's end of support in March 2026, R81's in October 2024 and R80.40's in April 2024; the Gaia lifecycle page carries every one of those dates. An R80.40 customer did not have three days. There was never a fix to apply.

F5: "not on the list" means not evaluated

CVE-2026-94127 is a heap-based buffer overflow in BIG-IP APM that allows unauthenticated remote code execution when APM is configured as an OAuth authorization server. F5 says plainly that it has learned the vulnerability has been exploited, and that Appliance mode is vulnerable too. The versions known to be vulnerable are 21.1.0, 17.5.0 to 17.5.1 and 17.1.0 to 17.1.3, each with an engineering hotfix.

Under every table in the advisory sits the same footnote:

F5 evaluates only software versions that have not yet reached the End of Technical Support (EoTS) phase of their lifecycle.

Those three branches are not a coincidence. They are exactly the three BIG-IP branches F5 still supports: 17.1.x to March 31, 2027, 17.5.x to January 1, 2029, and 21.1.x to May 5, 2029, the dates on the BIG-IP lifecycle page. Every branch below 17.1, from 16.1 (end of technical support July 31, 2025) back through 15.x, 14.x and older, is absent from the table because it was not examined. A reader who checks the affected list, finds no 16.1 row and concludes the branch is safe has read the table backwards. Absent is unevaluated, and unevaluated with a known exploited pre-auth RCE in the same code base is the worst square on the board.

Arista: fixes for "release trains under support"

CVE-2026-93952 is a CVSS 10.0 improper input validation flaw in on-prem VeloCloud Orchestrator, discovered externally and known to be actively exploited; the hosted and dedicated VCO services were patched before the advisory. Affected: 5.2.3.15 and below in the 5.2.x train, 6.1.3.7 and below in 6.1.x, 6.4.2.7 and below in 6.4.x, and 7.0.0.2 and below in 7.0.x. Fixed releases at publication: VCO 5.2.3.16 and later, and 6.4.2.8 and later, with the other trains to follow.

The resolution section says fixes are coming out for affected release trains under support. For everything else the advisory offers a phone number: customers not on a supported release train can contact TAC to discuss possible upgrade options for their release. That is the same shape as Arista's advisory for CVE-2026-16812 in July, which we covered in Exploited at CVSS 10.0, and the vendor never checked whether EOL versions are affected. Two months later, same product, same score, same carve-out.

The pattern, stated once

Three vendors with three different advisory styles reached the same position on the same afternoon. Check Point says it outright, in the table. F5 says it in a footnote repeated five times. Arista says it in the resolution paragraph. None of them is hiding anything; the words are all there. But the words describe a policy, not a risk assessment, and the risk does not respect the policy. A flaw in VPN certificate handling, in an OAuth server, or in an orchestrator's input validation does not know which release it is running in. The exploit that lands on R82 or 17.1.3 lands just as well on R80.40 or 16.1. The only difference is that one set of customers received a fix and the other received a lifecycle table.

This is what the EOL Risk Score is built to surface: a version past its vendor's fix window, in a product with entries in CISA's catalog, is scored on both conditions at once, because together they are the definition of unpatchable. The Exploited and Unpatchable feed tracks the cases where a KEV entry names a version that will never get the fix; this batch is being assessed for it.

What to do this week

Frequently asked questions

Which four vulnerabilities did CISA add on September 22, 2026?

CVE-2026-93952 in Arista VeloCloud Orchestrator (on-prem), CVE-2026-94127 in F5 BIG-IP APM, and CVE-2026-93616 and CVE-2026-85102 in Check Point Security Management and Security Gateway. All four carry a federal remediation due date of September 25, 2026 under BOD 26-04.

If my BIG-IP branch is not in F5's affected list, is it safe?

Not necessarily. F5's advisory states that it evaluates only software versions that have not yet reached the End of Technical Support phase of their lifecycle. The three branches listed as vulnerable, 21.1.x, 17.5.x and 17.1.x, are the only three BIG-IP branches F5 still supports. A branch below 17.1 was not evaluated, which is different from not vulnerable.

Is there a fix for Check Point R81.10, R81 or R80.x?

No. Check Point's advisory lists R81 and R81.10 as EOS for CVE-2026-85102, and R81.10 Take 190 or lower plus R80 through R81 as all EoS for CVE-2026-93616. Those releases are named as affected and receive no fix; the remedy is an upgrade to a supported release.

Sources

Related

© 2026 endoflife.ai · How we verify our dates · API · About