we_are_coded.by CODE · The world, decoded
БГ
CISA

Two holes in Check Point and one in Arista are being used in attacks, and part of on-premises Arista has no fix yet

Check Point Blog · event date: 22 September 2026Security

On 22 September CISA added three critical vulnerabilities to its catalogue of actively exploited ones. Check Point confirms attacks and has patches for both of its own. Arista says the hosted versions of VeloCloud Orchestrator are already patched, while for customer-installed ones fixes exist so far only for some release trains.

In short
  • CVE-2026-85102 is in the VPN of Check Point Security Gateway: the fix dates from 9 September, and attack attempts against Spark start on 12 September.
  • CVE-2026-93616 is a zero-day in Check Point Security Management; per the company, there were a handful of pinpointed attacks, observed on 23 July.
  • CVE-2026-93952 affects on-premises VeloCloud Orchestrator; fixes exist for the 5.2.3 and 6.4.2 trains, and for the rest Arista recommends restricted access until fixes arrive.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

The firewall is the last place you want a hole. It is the door, and everything passes through it.

Three such doors went into CISA's catalogue in one day. For all three there is an official vendor advisory, which I checked before writing.

The facts: on 22 September 2026 CISA added three entries to its Known Exploited Vulnerabilities (KEV) catalogue, with a deadline of 25 September for US federal agencies. CVE-2026-85102 (CVSS 9.8) is improper certificate validation during VPN negotiation in Check Point Security Gateway, allowing code execution without authentication; per Check Point the fix has been available since 9 September, and since 12 September the company has seen a wave of attempts against Spark customers. CVE-2026-93616 (CVSS 9.8) is a path traversal and file upload flaw in the Check Point Security Management web service that allows script execution without authentication; Check Point describes it as a zero-day with limited use, with a handful of pinpointed attacks observed on 23 July 2026, and released a fix on 22 September. CVE-2026-93952 (CVSS v4 9.5) is improper input validation in Arista VeloCloud Orchestrator installed on-premises: per Arista's advisory, a remote attacker without credentials can reach privileged internal functions, the hosted versions are already patched, fixes exist for the 5.2.3 train (from 5.2.3.16) and the 6.4.2 train (from 6.4.2.8), and fixes for the other affected trains will be added when ready.

Which one is more awkward

Arista. With Check Point the answer is simple, if unpleasant: you install the Jumbo Hotfix and check the logs for the traces they describe. With Arista, if you run the orchestrator yourself, there is a fix only for the 5.2.3 and 6.4.2 trains. For the rest there is nothing to install yet.

Their advice until then is honest and dull: web interface access only from trusted networks, monitoring for suspicious addresses, and keeping the logs. They also list addresses the attacks come from and traces to look for after an intrusion, while Arista warns there is no single definitive indicator.

When there is no patch, you close the door from the outside.

With Check Point there is one more detail. The fix for the VPN hole came out three days before the first wave of attempts. Whoever updated at once was protected, per Check Point. Whoever waited for a convenient moment was a target.

For Check Point, today is the day for the Jumbo Hotfix. For VeloCloud Orchestrator on your own server - the day to check whether your train has a fix, and if not, to hide its interface from the internet and watch Arista's advisory.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Check Point Blog - Security Advisory: Active Exploitation of CVE-2026-85102 and CVE-2026-93616, 22.09.2026→Check Point sk1000171 - CVE-2026-93616→Check Point sk1000117 - CVE-2026-85102→Arista Security Advisory 0183 - CVE-2026-93952, 22.09.2026→CISA: Known Exploited Vulnerabilities Catalog→CVE-2026-93952 (NVD)
Original: https://wearecoded.com/en/articles/check-point-arista-tri-dupki-kev.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news