F5 and Check Point Issue Emergency Patches for Zero-Day Flaws Exploited in Attacks

CISA orders federal agencies to patch F5 BIG-IP APM bug by Friday; Check Point hotfix addresses path traversal vulnerability in Security Management Server

By LineZotpaper
Published
Updated
Read Time3 min
Sources2 outlets
F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability (CVE-2026-94127) that is being actively exploited in remote code execution attacks, while Check Point also issued emergency hotfixes this week for a separate zero-day (CVE-2026-93616) targeting its Security Management Server. Both flaws are being exploited in the wild, prompting urgent warnings from the vendors and the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

F5 BIG-IP APM Zero-Day

F5 warned on Tuesday that the vulnerability, tracked as CVE-2026-94127, affects BIG-IP Access Policy Manager (APM) instances configured as an OAuth Authorization Server when an access policy and OAuth profile are set on a virtual server. According to F5, deployments using APM strictly as an OAuth Client or Resource Server are not affected.

"We have learned that this vulnerability has been exploited," F5 said in a security advisory. The company advised customers to review systems for indicators of compromise, such as multiple OAuth authentication failures followed by suspicious commands and a TMM SIGABRT.

Internet threat monitoring non-profit Shadowserver currently tracks over 14,700 IP addresses with BIG-IP APM fingerprints exposed online, though it is unclear how many are patched or are honeypots.

CISA added the flaw to its Known Exploited Vulnerabilities (KEV) Catalog and ordered U.S. federal agencies to secure their networks against it by Friday. For administrators who cannot immediately install updates, F5 has provided a mitigation iRule.

Check Point Security Management Server Zero-Day

Check Point released emergency hotfixes on Monday for a critical path traversal vulnerability (CVE-2026-93616) in its Security Management Server. The flaw allows unauthenticated attackers to upload and execute arbitrary scripts in low-complexity attacks.

Tracked as CVE-2026-93616, the vulnerability affects the Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Check Point addressed it in the R82.20 Security Hotfix.

"This vulnerability is exploited in the wild. Check Point is aware of a handful of customers who have been attacked," the company warned. It provided temporary mitigation measures including placing vulnerable systems behind a firewall and limiting access via Trusted Clients in SmartConsole.

Check Point also shared indicators of compromise in its security advisory. CISA and the FBI have urged software vendors since May 2024 to eliminate path traversal weaknesses from products before shipping, calling such issues "unforgivable."

Both vendors have been targeted by attackers in recent years. Two years ago, CISA flagged a Check Point Quantum Security Gateway flaw as actively exploited by ransomware gangs. F5 vulnerabilities have also been exploited by cybercrime and state-backed groups to breach corporate networks.

§

Analysis

Why This Matters

  • Both zero-days are actively exploited, giving attackers a foothold in enterprise networks that manage critical security infrastructure.
  • CISA's binding directive for the F5 bug means federal agencies must patch within days; private sector organizations face heightened risk if they delay.
  • The simultaneous disclosure underscores the persistent threat to widely used network security appliances.

Background

Network security appliances from F5 and Check Point are deployed globally to manage access, enforce policies, and monitor traffic. Because these devices sit at the network perimeter, successful exploits can grant attackers broad access to internal systems. Path traversal flaws (like the Check Point bug) and OAuth-related remote code execution vulnerabilities (like the F5 bug) are common vectors. Both companies have previously patched similar zero-day flaws exploited in ransomware and espionage campaigns.

Key Perspectives

F5 and Check Point: Both vendors released patches within days of learning of exploitation and provided temporary mitigations. They urged customers to deploy fixes urgently and check for indicators of compromise. CISA and FBI: Regulators are pushing for faster elimination of path traversal vulnerabilities through public guidance, and they mandate federal patching via the KEV catalog. The FBI/CISA joint statement called path traversal flaws "unforgivable." Attackers: Exploitation of these bugs gives adversaries the ability to execute arbitrary commands, steal credentials, or deploy ransomware. The Check Point advisory notes a handful of victims; the F5 advisory confirms exploitation but does not specify scope.

What to Watch

  • Patching rate: Whether organizations apply the hotfixes before attackers scan for unpatched systems.
  • Further indicators of compromise: Both vendors may update advisories as more attack data emerges.
  • Attribution: Whether the same or different threat actors are exploiting these zero-days, and whether they are linked to known ransomware groups.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.