Vulnerabilities & Exploits · Web App Attack

Check Point and F5 Flaws Break Control Planes

Check Point and F5 both said Tuesday that attackers are actively exploiting zero-days in products that sit at the control point: Check Point’s Management Server family and F5’s BIG-IP Access Policy Manager. The issues are tracked as CVE-2026-93616 and CVE-2026-94127, and both vendors have now moved from disclosure to emergency fixes and exposure limits.

On the Check Point side, unauthenticated attackers can abuse a directory-traversal and file-upload bug in the Management Web Service to upload and run scripts. On the F5 side, specially crafted traffic to a virtual server with BIG-IP APM and an OAuth profile can trigger code execution before login. In both cases, the vulnerable layer is not just another host: it is the place that brokers policy, access, or fleet management.

That makes the blast radius bigger than the appliance itself. If Check Point manages other security gear, or if F5 sits in front of application access, a hit on the box can become a hit on the systems and sessions it controls, and the remaining exposure is whoever still leaves that control point reachable from untrusted networks.

14 sources · Sep 24

CVE-2026-93616

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: a directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute…

CISA federal remediation date Sep 25

CVE-2026-94127

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: when a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic…

CISA federal remediation date Sep 25

Timeline

Sources

Vendor digest: F5

Part of the PlainSec briefing for 2026-09-22

Every edition of this story: Check Point and F5 Flaws Break Control Planes

More from today