Security Roundup: F5 BIG-IP APM Buffer Overflow, Check Point Management Zero-Day, Arista VeloCloud in CISA KEV (Week of September 25, 2026)
Executive Summary: The final week of September 2026 witnessed an unprecedented wave of critical edge infrastructure and enterprise appliance disclosures. CISA added three high-impact zero-days to the Known Exploited Vulnerabilities catalog: an unauthenticated heap-based buffer overflow in F5 BIG-IP Access Policy Manager (CVE-2026-94127, CVSS 9.8), an actively exploited path traversal flaw in Check Point Security Management Server (CVE-2026-93616, CVSS 9.8), and a maximum-severity certificate validation bypass in Arista VeloCloud SD-WAN Orchestrator (CVE-2026-93952, CVSS 10.0). We also break down the CLEANGULP browser-to-kernel zero-day chain and present an actionable blueprint for securing next-gen edge architectures.
Key Threat Disclosures at a Glance
1. F5 BIG-IP APM OAuth Heap Buffer Overflow (CVE-2026-94127)
When F5 BIG-IP Access Policy Manager (APM) is configured as an OAuth Authorization Server, a heap-based buffer overflow in the token validation subsystem allows unauthenticated remote attackers to execute arbitrary shellcode with root privileges. CISA mandated immediate emergency remediation across all federal civilian executive branch networks.
2. Check Point Security Management Server Path Traversal (CVE-2026-93616)
Check Point published an emergency security advisory for an actively exploited zero-day vulnerability in its Security Management Server's web service on port 19009. Unauthenticated attackers can traverse directory structures, upload arbitrary scripts, and take complete control over centralized firewall policies.
3. Arista VeloCloud SD-WAN Orchestrator Authentication Bypass (CVE-2026-93952)
Affecting on-premises VeloCloud Orchestrator (VCO) deployments, this CVSS 10.0 improper input validation flaw allows an attacker with public edge certificate keys to bypass authentication boundaries and invoke privileged administrative APIs across the SD-WAN mesh.
4. CLEANGULP: Browser Sandbox Breakout to Windows Kernel SYSTEM
Threat intelligence researchers documented the CLEANGULP campaign, which chains a Google Chrome V8 engine type-confusion bug with Microsoft’s actively exploited Windows ALPC zero-day (CVE-2026-85880) to achieve zero-interaction remote compromise and kernel privilege escalation.
Technical Deep Dives in This Series
- CVE-2026-94127: F5 BIG-IP APM OAuth Heap Buffer Overflow RCE: Heap layout, token parsing mechanics, and RCE exploitation analysis in F5 APM.
- CVE-2026-93616: Check Point Management Server Zero-Day: Port 19009 web service inspection, path traversal mechanics, and policy tampering IOCs.
- CVE-2026-93952: Arista VeloCloud SD-WAN CVSS 10.0 Flaw: Cryptographic certificate validation failure and SD-WAN fabric takeover mechanics.
- CLEANGULP Exploit Chain: Chrome V8 to Windows ALPC Zero-Day: Reverse engineering the CLEANGULP multi-stage exploit chain from browser to kernel.
- Hardening Next-Gen Edge: SD-WAN, ADC & Management Defense: Engineering blueprint for securing SD-WAN orchestrators, ADCs, and central management consoles.
Weekly Action Checklist for Security Teams
- Patch F5 BIG-IP Appliances: Apply official F5 engineering hotfixes across versions 17.1.x, 17.5.x, and 21.1.x immediately.
- Deploy Check Point Jumbo Hotfix: Install the R82.20 security hotfix and restrict TCP port 19009 access exclusively to isolated admin subnets.
- Audit VeloCloud Orchestrators: Upgrade VCO deployments to patched releases and rotate edge authentication certificates.
- Update Chrome & Windows Endpoints: Ensure all enterprise workstations are updated with Microsoft’s September Patch Tuesday and Chrome 128+ binaries.