CISA added four exploited flaws in Check Point, F5 BIG-IP and Arista VeloCloud on September 22, 2026, due September 25. Every fix stops at end of support.
The four entries
| CVE | Vendor and product | CVSS | Added to KEV | Federal due date |
|---|---|---|---|---|
| CVE-2026-93952 | Arista VeloCloud Orchestrator (on-prem) | 10.0 | September 22, 2026 | September 25, 2026 |
| CVE-2026-94127 | F5 BIG-IP APM | 9.8 | September 22, 2026 | September 25, 2026 |
| CVE-2026-93616 | Check Point Security Management | 9.8 | September 22, 2026 | September 25, 2026 |
| CVE-2026-85102 | Check Point Security Gateway and Spark | 9.8 | September 22, 2026 | September 25, 2026 |
What's covered
- The four entries
- Check Point: the unsupported releases are named, and marked EoS
- F5: "not on the list" means not evaluated
- Arista: fixes for "release trains under support"
- The pattern, stated once
- What to do this week
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-checkpoint-f5-arista-kev-end-of-support
Top comments (0)