Security Roundup: F5 BIG-IP APM Buffer Overflow, Check Point Management Zero-Day, Arista VeloCloud in CISA KEV (Week of September 25, 2026)

ColibriSec Weekly Security Roundup September 25 2026

Executive Summary: The final week of September 2026 witnessed an unprecedented wave of critical edge infrastructure and enterprise appliance disclosures. CISA added three high-impact zero-days to the Known Exploited Vulnerabilities catalog: an unauthenticated heap-based buffer overflow in F5 BIG-IP Access Policy Manager (CVE-2026-94127, CVSS 9.8), an actively exploited path traversal flaw in Check Point Security Management Server (CVE-2026-93616, CVSS 9.8), and a maximum-severity certificate validation bypass in Arista VeloCloud SD-WAN Orchestrator (CVE-2026-93952, CVSS 10.0). We also break down the CLEANGULP browser-to-kernel zero-day chain and present an actionable blueprint for securing next-gen edge architectures.

🏛️
Incident Overview:

Key Threat Disclosures at a Glance

1. F5 BIG-IP APM OAuth Heap Buffer Overflow (CVE-2026-94127)

When F5 BIG-IP Access Policy Manager (APM) is configured as an OAuth Authorization Server, a heap-based buffer overflow in the token validation subsystem allows unauthenticated remote attackers to execute arbitrary shellcode with root privileges. CISA mandated immediate emergency remediation across all federal civilian executive branch networks.

2. Check Point Security Management Server Path Traversal (CVE-2026-93616)

Check Point published an emergency security advisory for an actively exploited zero-day vulnerability in its Security Management Server's web service on port 19009. Unauthenticated attackers can traverse directory structures, upload arbitrary scripts, and take complete control over centralized firewall policies.

3. Arista VeloCloud SD-WAN Orchestrator Authentication Bypass (CVE-2026-93952)

Affecting on-premises VeloCloud Orchestrator (VCO) deployments, this CVSS 10.0 improper input validation flaw allows an attacker with public edge certificate keys to bypass authentication boundaries and invoke privileged administrative APIs across the SD-WAN mesh.

4. CLEANGULP: Browser Sandbox Breakout to Windows Kernel SYSTEM

Threat intelligence researchers documented the CLEANGULP campaign, which chains a Google Chrome V8 engine type-confusion bug with Microsoft’s actively exploited Windows ALPC zero-day (CVE-2026-85880) to achieve zero-interaction remote compromise and kernel privilege escalation.

Technical Deep Dives in This Series

Weekly Action Checklist for Security Teams

  1. Patch F5 BIG-IP Appliances: Apply official F5 engineering hotfixes across versions 17.1.x, 17.5.x, and 21.1.x immediately.
  2. Deploy Check Point Jumbo Hotfix: Install the R82.20 security hotfix and restrict TCP port 19009 access exclusively to isolated admin subnets.
  3. Audit VeloCloud Orchestrators: Upgrade VCO deployments to patched releases and rotate edge authentication certificates.
  4. Update Chrome & Windows Endpoints: Ensure all enterprise workstations are updated with Microsoft’s September Patch Tuesday and Chrome 128+ binaries.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther