Menu Close

Today’s Virus Report: September 24, 2026

Virus Report, viruses

The cyber threat environment requires immediate action this week. Federal authorities added four severe software bugs to their active threat lists over the past 48 hours. Hackers continue attacking unpatched network gateways at a high rate. Attackers use these hardware flaws to break into corporate networks without needing employee passwords.

Monitoring active threats requires strict patching routines and reliable intelligence. Reading direct alerts from the Cybersecurity and Infrastructure Security Agency provides IT departments with the exact technical steps needed to secure vulnerable networks today.

Check Point and F5 BIG-IP Under Attack

Hardware devices that manage remote access create a massive target for cybercriminals. The government recently added two critical vulnerabilities affecting Check Point network security products to its Known Exploited Vulnerabilities catalog. Tracked as CVE-2026-85102 and CVE-2026-93616, these flaws allow hackers to bypass certificate checks and read sensitive files stored outside the target directory.

At the same time, threat actors actively exploit a heap-based buffer overflow in F5 BIG-IP Access Policy Manager. Tracked as CVE-2026-94127, this bug lets remote hackers execute malicious code directly on the appliance. Attackers use this access to plant hidden backdoors on the network. Applying vulnerability management standards published by the National Institute of Standards and Technology helps administrators isolate these compromised gateways from internal servers.

Virus F5 BIG_IP

Arista VeloCloud and Healthcare Extortion

The threat environment remains highly dangerous for organizations running cloud-managed networking tools. Recent intelligence confirms active exploitation of CVE-2026-93952, a severe input validation bug in Arista VeloCloud Orchestrator. Hackers use this flaw to run malicious code remotely, putting any business with this infrastructure at severe risk.

Extortion groups target the healthcare and financial sectors heavily this week. Ransomware syndicates steal terabytes of private patient records before locking the hospital servers. They use compromised third-party payment gateways and cloud storage apps to gain entry. Tracking these intrusion methods through our active virus campaigns database helps defenders spot early warning signs before a hacker steals internal data.

September 24 Active Threat Data

Security teams must prioritize the immediate dangers circulating today. The table below outlines the primary targets and methods of these active threats.

Threat Target / FlawPrimary Attack MethodMain Operational Goal
Check Point ProductsCVE-2026-93616 path traversalReading sensitive system files remotely
F5 BIG-IP APMCVE-2026-94127 buffer overflowRunning malicious code on access gateways
Arista VeloCloudCVE-2026-93952 input validationBreaching cloud network orchestrators
Healthcare NetworksThird-party software exploitsStealing medical records and deploying ransomware

Steps to Secure Your Network Today

Administrators must enforce strict security protocols to survive this environment. Never assume your servers are safe using default firewall settings. The ongoing attacks on F5 and Check Point gateways prove that modern threats bypass standard defenses easily.

Update all external software immediately. Prioritize patches for internet-facing systems like remote access gateways and cloud orchestrators. Isolate any system exhibiting signs of unusual administrative traffic. Reviewing technical mitigation strategies through the SANS Institute guarantees you apply the correct hardening measures for your data centers.

CISA vulnerabilities update

Watch this video to learn more about how CISA expands its Known Exploited Vulnerabilities catalog to help organizations respond quickly to active cyber threats.