The cyber threat environment requires immediate action this week. Federal authorities added four severe software bugs to their active threat lists over the past 48 hours. Hackers continue attacking unpatched network gateways at a high rate. Attackers use these hardware flaws to break into corporate networks without needing employee passwords.
Monitoring active threats requires strict patching routines and reliable intelligence. Reading direct alerts from the Cybersecurity and Infrastructure Security Agency provides IT departments with the exact technical steps needed to secure vulnerable networks today.
Check Point and F5 BIG-IP Under Attack
Hardware devices that manage remote access create a massive target for cybercriminals. The government recently added two critical vulnerabilities affecting Check Point network security products to its Known Exploited Vulnerabilities catalog. Tracked as CVE-2026-85102 and CVE-2026-93616, these flaws allow hackers to bypass certificate checks and read sensitive files stored outside the target directory.
At the same time, threat actors actively exploit a heap-based buffer overflow in F5 BIG-IP Access Policy Manager. Tracked as CVE-2026-94127, this bug lets remote hackers execute malicious code directly on the appliance. Attackers use this access to plant hidden backdoors on the network. Applying vulnerability management standards published by the National Institute of Standards and Technology helps administrators isolate these compromised gateways from internal servers.

Arista VeloCloud and Healthcare Extortion
The threat environment remains highly dangerous for organizations running cloud-managed networking tools. Recent intelligence confirms active exploitation of CVE-2026-93952, a severe input validation bug in Arista VeloCloud Orchestrator. Hackers use this flaw to run malicious code remotely, putting any business with this infrastructure at severe risk.
Extortion groups target the healthcare and financial sectors heavily this week. Ransomware syndicates steal terabytes of private patient records before locking the hospital servers. They use compromised third-party payment gateways and cloud storage apps to gain entry. Tracking these intrusion methods through our active virus campaigns database helps defenders spot early warning signs before a hacker steals internal data.
September 24 Active Threat Data
Security teams must prioritize the immediate dangers circulating today. The table below outlines the primary targets and methods of these active threats.
| Threat Target / Flaw | Primary Attack Method | Main Operational Goal |
| Check Point Products | CVE-2026-93616 path traversal | Reading sensitive system files remotely |
| F5 BIG-IP APM | CVE-2026-94127 buffer overflow | Running malicious code on access gateways |
| Arista VeloCloud | CVE-2026-93952 input validation | Breaching cloud network orchestrators |
| Healthcare Networks | Third-party software exploits | Stealing medical records and deploying ransomware |
Steps to Secure Your Network Today
Administrators must enforce strict security protocols to survive this environment. Never assume your servers are safe using default firewall settings. The ongoing attacks on F5 and Check Point gateways prove that modern threats bypass standard defenses easily.
Update all external software immediately. Prioritize patches for internet-facing systems like remote access gateways and cloud orchestrators. Isolate any system exhibiting signs of unusual administrative traffic. Reviewing technical mitigation strategies through the SANS Institute guarantees you apply the correct hardening measures for your data centers.
Watch this video to learn more about how CISA expands its Known Exploited Vulnerabilities catalog to help organizations respond quickly to active cyber threats.