CVE-2026-93616
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute…
CISA federal remediation date Sep 25
Vulnerabilities & Exploits · Web App Attack
Check Point and F5 both said Tuesday that attackers are actively exploiting zero-days in products that sit at the control point: Check Point’s Management Server family and F5’s BIG-IP Access Policy Manager. The issues are tracked as CVE-2026-93616 and CVE-2026-94127, and both vendors have now moved from disclosure to emergency fixes and exposure limits.
On the Check Point side, unauthenticated attackers can abuse a directory-traversal and file-upload bug in the Management Web Service to upload and run scripts. On the F5 side, specially crafted traffic to a virtual server with BIG-IP APM and an OAuth profile can trigger code execution before login. In both cases, the vulnerable layer is not just another host: it is the place that brokers policy, access, or fleet management.
That makes the blast radius bigger than the appliance itself. If Check Point manages other security gear, or if F5 sits in front of application access, a hit on the box can become a hit on the systems and sessions it controls, and the remaining exposure is whoever still leaves that control point reachable from untrusted networks.
14 sources · Sep 24
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute…
CISA federal remediation date Sep 25
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: when a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic…
CISA federal remediation date Sep 25
CSO Online
F5 fixes actively exploited zero-day flaw in BIG-IP APM
The critical remote code execution vulnerability was added to CISA’s KEV, with more than 15,000 deployments potentially at risk.
originalThe Register Security
Someone's attacking a critical 0-day RCE in F5 BIG-IP APM
Bad news: both CISA and F5 warn that it's under active exploitation
originalCERT Polska
Vulnerability in WEBCON BPS software
Authorization bypass through User-Controlled key vulnerability (CVE-2026-92419) has been found in WEBCON BPS software.
originalPart of the PlainSec briefing for 2026-09-22
Every edition of this story: Check Point and F5 Flaws Break Control Planes