On 22 September CISA added three critical vulnerabilities to its catalogue of actively exploited ones. Check Point confirms attacks and has patches for both of its own. Arista says the hosted versions of VeloCloud Orchestrator are already patched, while for customer-installed ones fixes exist so far only for some release trains.
- CVE-2026-85102 is in the VPN of Check Point Security Gateway: the fix dates from 9 September, and attack attempts against Spark start on 12 September.
- CVE-2026-93616 is a zero-day in Check Point Security Management; per the company, there were a handful of pinpointed attacks, observed on 23 July.
- CVE-2026-93952 affects on-premises VeloCloud Orchestrator; fixes exist for the 5.2.3 and 6.4.2 trains, and for the rest Arista recommends restricted access until fixes arrive.
The firewall is the last place you want a hole. It is the door, and everything passes through it.
Three such doors went into CISA's catalogue in one day. For all three there is an official vendor advisory, which I checked before writing.
Which one is more awkward
Arista. With Check Point the answer is simple, if unpleasant: you install the Jumbo Hotfix and check the logs for the traces they describe. With Arista, if you run the orchestrator yourself, there is a fix only for the 5.2.3 and 6.4.2 trains. For the rest there is nothing to install yet.
Their advice until then is honest and dull: web interface access only from trusted networks, monitoring for suspicious addresses, and keeping the logs. They also list addresses the attacks come from and traces to look for after an intrusion, while Arista warns there is no single definitive indicator.
With Check Point there is one more detail. The fix for the VPN hole came out three days before the first wave of attempts. Whoever updated at once was protected, per Check Point. Whoever waited for a convenient moment was a target.
For Check Point, today is the day for the Jumbo Hotfix. For VeloCloud Orchestrator on your own server - the day to check whether your train has a fix, and if not, to hide its interface from the internet and watch Arista's advisory.