Three Vendors Shipped Emergency Fixes. All Stopped at End of Support.
On September 22, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog in a single batch and gave federal agencies until September 25, 2026 to fix them. Three vendors, four CVEs, one deadline. What makes the batch worth a page of its own is not the flaws. It is that all three vendors published advisories the same day, and every one of those advisories stops at the end-of-support line. If you run an end-of-support release of Check Point, BIG-IP or VeloCloud Orchestrator, the vendor's own document says, in its own words, that no fix is coming.
The four entries
| CVE | Vendor and product | CVSS | Added to KEV | Federal due date |
|---|---|---|---|---|
| CVE-2026-93952 | Arista VeloCloud Orchestrator (on-prem) | 10.0 | September 22, 2026 | September 25, 2026 |
| CVE-2026-94127 | F5 BIG-IP APM | 9.8 | September 22, 2026 | September 25, 2026 |
| CVE-2026-93616 | Check Point Security Management | 9.8 | September 22, 2026 | September 25, 2026 |
| CVE-2026-85102 | Check Point Security Gateway and Spark | 9.8 | September 22, 2026 | September 25, 2026 |
Source: CISA's Known Exploited Vulnerabilities catalog, read from the live JSON feed. Each vendor's advisory was then read in full; the quotations below are theirs.
Check Point: the unsupported releases are named, and marked EoS
Check Point's advisory covers two flaws. CVE-2026-85102 is a pre-authentication remote code execution vulnerability in the Security Gateway's VPN certificate handling. Check Point released fixes on September 9, 2026 with no evidence of exploitation at the time; starting September 12, 2026 it observed a wave of exploitation attempts against Spark customers. A supported customer had three days between fix and attack. CVE-2026-93616 is a zero-day in Security Management with a fix published the same day as the advisory.
The affected-versions tables do something most vendors avoid: they list the end-of-support releases as affected and label them. For CVE-2026-85102 the list reads R81 (EOS), R81.10 (EOS), then the supported R81.10.X, R81.20, R82, R82.00.X and R82.10. For CVE-2026-93616 the list ends with R81.10 Take 190 or lower (EoS) and R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS). Seven releases, affected, no fix. Check Point's own support life-cycle table puts R81.10's end of support in March 2026, R81's in October 2024 and R80.40's in April 2024; the Gaia lifecycle page carries every one of those dates. An R80.40 customer did not have three days. There was never a fix to apply.
F5: "not on the list" means not evaluated
CVE-2026-94127 is a heap-based buffer overflow in BIG-IP APM that allows unauthenticated remote code execution when APM is configured as an OAuth authorization server. F5 says plainly that it has learned the vulnerability has been exploited, and that Appliance mode is vulnerable too. The versions known to be vulnerable are 21.1.0, 17.5.0 to 17.5.1 and 17.1.0 to 17.1.3, each with an engineering hotfix.
Under every table in the advisory sits the same footnote:
F5 evaluates only software versions that have not yet reached the End of Technical Support (EoTS) phase of their lifecycle.
Those three branches are not a coincidence. They are exactly the three BIG-IP branches F5 still supports: 17.1.x to March 31, 2027, 17.5.x to January 1, 2029, and 21.1.x to May 5, 2029, the dates on the BIG-IP lifecycle page. Every branch below 17.1, from 16.1 (end of technical support July 31, 2025) back through 15.x, 14.x and older, is absent from the table because it was not examined. A reader who checks the affected list, finds no 16.1 row and concludes the branch is safe has read the table backwards. Absent is unevaluated, and unevaluated with a known exploited pre-auth RCE in the same code base is the worst square on the board.
Arista: fixes for "release trains under support"
CVE-2026-93952 is a CVSS 10.0 improper input validation flaw in on-prem VeloCloud Orchestrator, discovered externally and known to be actively exploited; the hosted and dedicated VCO services were patched before the advisory. Affected: 5.2.3.15 and below in the 5.2.x train, 6.1.3.7 and below in 6.1.x, 6.4.2.7 and below in 6.4.x, and 7.0.0.2 and below in 7.0.x. Fixed releases at publication: VCO 5.2.3.16 and later, and 6.4.2.8 and later, with the other trains to follow.
The resolution section says fixes are coming out for affected release trains under support. For everything else the advisory offers a phone number: customers not on a supported release train can contact TAC to discuss possible upgrade options for their release. That is the same shape as Arista's advisory for CVE-2026-16812 in July, which we covered in Exploited at CVSS 10.0, and the vendor never checked whether EOL versions are affected. Two months later, same product, same score, same carve-out.
The pattern, stated once
Three vendors with three different advisory styles reached the same position on the same afternoon. Check Point says it outright, in the table. F5 says it in a footnote repeated five times. Arista says it in the resolution paragraph. None of them is hiding anything; the words are all there. But the words describe a policy, not a risk assessment, and the risk does not respect the policy. A flaw in VPN certificate handling, in an OAuth server, or in an orchestrator's input validation does not know which release it is running in. The exploit that lands on R82 or 17.1.3 lands just as well on R80.40 or 16.1. The only difference is that one set of customers received a fix and the other received a lifecycle table.
This is what the EOL Risk Score is built to surface: a version past its vendor's fix window, in a product with entries in CISA's catalog, is scored on both conditions at once, because together they are the definition of unpatchable. The Exploited and Unpatchable feed tracks the cases where a KEV entry names a version that will never get the fix; this batch is being assessed for it.
What to do this week
- Check Point. Any gateway or management server on R81.10 or older is affected with no fix. The remedy is the upgrade to R81.20 or later plus the Jumbo Hotfix take named in Check Point's advisory (sk1000117 and sk1000171). Spark appliances are the ones seeing the exploitation wave.
- BIG-IP. If APM runs as an OAuth authorization server on 21.1, 17.5 or 17.1, apply the engineering hotfix. If it runs on a branch below 17.1, treat the device as exposed and plan the branch upgrade; F5's iRule mitigation is available through support in the meantime.
- VeloCloud Orchestrator on-prem. Move 5.2.x and 6.4.x to the fixed builds now; watch the advisory for the 6.1.x and 7.0.x fixes; anything older goes through TAC. Restrict the VCO web interface to administrative networks regardless, and review the indicators of compromise Arista lists, including two named source IPs and a planted service file.
- Everyone. Put the lifecycle dates for these three products in the same place as the CVE tracker. The API serves both together:
curl https://api.endoflife.ai/v1/score/big-ip/16.1returns the end-of-technical-support date, the CISA KEV exposure and the score in one response.
Frequently asked questions
Which four vulnerabilities did CISA add on September 22, 2026?
CVE-2026-93952 in Arista VeloCloud Orchestrator (on-prem), CVE-2026-94127 in F5 BIG-IP APM, and CVE-2026-93616 and CVE-2026-85102 in Check Point Security Management and Security Gateway. All four carry a federal remediation due date of September 25, 2026 under BOD 26-04.
If my BIG-IP branch is not in F5's affected list, is it safe?
Not necessarily. F5's advisory states that it evaluates only software versions that have not yet reached the End of Technical Support phase of their lifecycle. The three branches listed as vulnerable, 21.1.x, 17.5.x and 17.1.x, are the only three BIG-IP branches F5 still supports. A branch below 17.1 was not evaluated, which is different from not vulnerable.
Is there a fix for Check Point R81.10, R81 or R80.x?
No. Check Point's advisory lists R81 and R81.10 as EOS for CVE-2026-85102, and R81.10 Take 190 or lower plus R80 through R81 as all EoS for CVE-2026-93616. Those releases are named as affected and receive no fix; the remedy is an upgrade to a supported release.
Sources
- CISA, Known Exploited Vulnerabilities catalog, entries dated 2026-09-22 (live feed).
- Check Point, security advisory for CVE-2026-85102 and CVE-2026-93616, blog.checkpoint.com, September 22, 2026.
- F5, K000162605: BIG-IP APM vulnerability CVE-2026-94127, published and updated September 22, 2026; K5903 for branch end-of-technical-support dates.
- Arista, Security Advisory 0183, September 22, 2026.
Related
- Check Point Gaia lifecycle and F5 BIG-IP lifecycle — every release with its date and live score
- Arista VeloCloud, July 2026 — the first time this vendor made this argument
- Exploited and Unpatchable — KEV entries that name versions that will never get the fix