On September 22, CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog in a single update: a Check Point Security Gateway pre-auth VPN RCE, a Check Point Management Server path-traversal flaw, an Arista VeloCloud Orchestrator input-validation bug rated a perfect CVSS 10.0, and an F5 BIG-IP Access Policy Manager buffer overflow that allows unauthenticated code execution. Three vendors, four CVEs, zero authentication required for any of them, and a compressed September 25 federal remediation deadline that gives agencies roughly 72 hours from disclosure to patch.
That’s not a coincidence of scheduling. It’s a snapshot of where the exploitation economy is currently pointed: the network edge, specifically the appliances that terminate VPN sessions, manage remote access policy, and orchestrate SD-WAN traffic for large enterprises. These aren’t endpoint bugs that need a phishing click to matter. They sit on the internet-facing perimeter by design, and all four were being exploited before CISA’s catalog entry made them public. Check Point confirmed exploitation attempts against its Spark customers began September 12, three days after the company had already shipped fixes. Attackers were reverse-engineering the patch faster than customers were deploying it.
What four simultaneous KEV entries actually tell you
The individual technical details matter less than the pattern across them. CVE-2026-85102 and CVE-2026-93616 (Check Point) target the VPN gateway and management plane, the two components an organization relies on to secure and administer remote access. CVE-2026-93952 (Arista VeloCloud) hits SD-WAN orchestration, meaning a successful exploit can potentially touch every branch office the orchestrator manages, not just one appliance. CVE-2026-94127 (F5 BIG-IP APM) hits access policy management, the system that decides who gets through the gateway at all. Compromise any one of these categories and you don’t need to move laterally to get organization-wide reach. The device you’d trust to keep attackers out is the one doing the work of letting them in.
This is a continuation of a trend this pipeline has tracked all year, not a new one. Ivanti, Fortinet, Citrix, Palo Alto, and now Check Point, Arista, and F5 have each supplied at least one pre-auth, remotely exploitable network-edge CVE to the KEV catalog in 2026. The read that matters is attacker economics, not vendor security quality: perimeter appliances are closed-source, rarely instrumented with EDR, and administered by network teams whose patch cadence runs on change-control windows rather than emergency response. A researcher or exploit broker who finds a bug in one of these products gets a target population that is slow to patch, hard to monitor, and high in privilege, a combination worth more on the exploit market than an equivalent desktop bug where EDR and faster patch cycles shrink the window of usefulness. The vendors are not the common thread. The deployment model is.
The Check Point timeline is the cleanest evidence of how tight that window has become: patches shipped, and within 72 hours, in-the-wild exploitation attempts against customers who hadn’t yet applied them. That’s a patch-gap measured in days, not the weeks most of 2026’s KEV entries have run on, which means treating a CVSS 10.0 SD-WAN bug or an unauthenticated VPN RCE as “next maintenance window” material is functionally choosing to lose the race. The September 25 federal deadline is a floor, not a target. For any organization running these products at the edge, this week’s action item was “patch before September 22,” and if that didn’t happen, the operating assumption should shift to compromise-hunting rather than patch-and-move-on.
There’s a second-order defender problem here, easy to miss because none of the four CVEs individually reads as catastrophic outside its own advisory. Teams triaging KEV additions one vendor at a time will patch each appliance as its own ticket, against its own blast radius; none of these four scream “drop everything” alone. Triaged as a set, on the same day, they describe an attacker population actively working the entire remote-access perimeter at once, not a single opportunistic actor who found one bug. Whether that reflects shared tooling, a common exploit-research pipeline, or independent discovery converging on the same product category isn’t yet public, but the operational response is the same regardless: any unauthenticated, internet-facing edge appliance deserves this week’s urgency, whether or not its name has shown up in a KEV update yet.
The FBI breach claim and what’s actually confirmed
Running in parallel, extortion group ShinyHunters claimed on September 22 that it exploited a previously unknown Oracle PeopleSoft vulnerability to access internal FBI systems, alleging 2 to 3 terabytes of data including records on nearly all FBI agents and job applicants, and published a sample of roughly 5,000 records alongside a screenshot purportedly from a compromised FBIjobs.gov backend. The FBI confirmed it is investigating but has not confirmed the intrusion itself. ShinyHunters framed the operation as retaliation for a May FBI advisory that named the group’s tactics and told victims not to pay.
Treat the claim as unconfirmed until the FBI or a credible third party validates the sample data and the alleged PeopleSoft flaw, but don’t dismiss it as noise. ShinyHunters has a track record of Oracle-adjacent extortion campaigns with real victims behind the claims, and the retaliatory framing against a named federal advisory is a notable escalation in target selection regardless of how the technical details resolve. If the PeopleSoft zero-day claim holds up, any organization running PeopleSoft HR or applicant-tracking modules with internet-facing components has an unpatched exposure with no CVE assigned, no KEV entry, and no patch to apply. Watch for Oracle’s response and for additional alleged PeopleSoft victims on the group’s extortion site.
The water sector pattern keeps expanding
Colorado officials disclosed on September 22 that a foreign threat actor briefly accessed two small private water utilities serving roughly 200 people in late August, altering pump cycles and disabling remote access alarms. Water treatment and quality were never at risk, and attribution remains formally unconfirmed, though the governor’s office referenced awareness of Iran-linked targeting of U.S. water and wastewater systems without tying it directly to this incident. This extends a 2026 pattern now covering more than 100 water systems across at least 12 states.
The victim profile is the point. These are not large municipal utilities with dedicated OT security staff; they’re small private operators running internet-facing human-machine interfaces because that’s the only remote-access model within their budget. The attacker capability required to touch pump cycles and disable alarms at this scale is modest. What’s escalating isn’t sophistication, it’s persistence and breadth: a foreign actor working down a list of exposed small water systems methodically enough to hit 100-plus in a year. Consequence has stayed low because these systems are small and the actor hasn’t chosen to cause harm, not because the access was hard to get or hard to weaponize into something worse.
What to watch
Two threads carry into next week: whether Oracle or the FBI confirms any part of the ShinyHunters PeopleSoft claim, converting an unverified extortion post into a real zero-day with no current patch, and whether exploitation of the Check Point, Arista, or F5 KEV entries produces confirmed downstream breaches rather than just scanning and access attempts. Given how much of 2026’s ransomware initial-access activity has traced back to earlier network-edge KEV entries, a repeat here would be the expected outcome, not a surprising one.
Security Unlocked publishes threat intelligence and strategic analysis twice weekly. This mid-week brief covers developments from September 21, 2026 through September 24, 2026.
Security