CISA's list that day
22 September 2026
On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Check Point Multiple Products, Arista VeloCloud Orchestrator and F5 BIG-IP APM. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-93616Path Traversal | Check Point Multiple Products | Patch nowForensic triage required by CISA | 0.20 | ||
| CVE-2026-85102Improper Certificate Validation | Check Point Multiple Products | Patch nowForensic triage required by CISA | 0.08 | ||
| CVE-2026-94127Heap-based Buffer Overflow | F5 BIG-IP APM | Patch nowForensic triage required by CISA | 0.02 | ||
| CVE-2026-93952Improper Input Validation | Arista VeloCloud Orchestrator | Patch nowForensic triage required by CISA | 0.01 |