Introduction
This week’s weekly cybersecurity news highlights an escalating wave of attacks aimed directly at critical edge infrastructure and public-sector personnel databases. Security teams faced emergency disclosures involving actively targeted enterprise gateways, alongside high-stakes breach claims targeting federal recruitment portals.
Threat actors continue to exploit administrative interfaces and boundary devices before organizations can complete standard patch cycles. Consequently, security leaders must prioritize edge visibility, patch verification, and rapid credential containment.
Top Cybersecurity Stories This Week
F5 BIG-IP APM Buffer Overflow Added to CISA KEV (CVE-2026-94127)
On September 22, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added a critical heap-based buffer overflow flaw affecting F5 BIG-IP Access Policy Manager (APM) to its Known Exploited Vulnerabilities (KEV) Catalog. The issue allows an unauthenticated remote attacker to execute arbitrary code or trigger a denial-of-service state on exposed gateway interfaces. Furthermore, active exploitation in the wild prompted federal binding operational directives mandating rapid remediation.
- Identified CVEs: CVE-2026-94127 (CVSS Score pending official NVD baseline; classified by vendor as Critical)
- Attack Vector: Remote memory corruption via crafted network requests targeting the APM authentication handling subsystem.
- Source & Verification: CISA Known Exploited Vulnerabilities Catalog Alert (September 22, 2026)
Arista VeloCloud Orchestrator Zero-Day Exploitation (CVE-2026-93952)
Arista addressed an input validation flaw in VeloCloud Orchestrator following confirmed reports of in-the-wild exploitation. CISA cataloged the issue on September 22, 2026, warning that threat actors targeted publicly exposed orchestrators to bypass controls and run unauthorized commands. Because SD-WAN orchestrators serve as central management hubs for distributed networks, compromise grants attackers broad reach into interconnected corporate branches.
- Identified CVEs: CVE-2026-93952 (CVSS Score pending; classified as High/Critical)
- Attack Vector: Improper input validation within administrative API endpoints, leading to command injection and configuration tampering.
- Source & Verification: CISA Alert: Catalog Addition for Arista VeloCloud
Dual Check Point Management Server Vulnerabilities Under Active Attack
CISA also added two vulnerabilities affecting Check Point security management products to the KEV catalog on September 22, 2026. Attackers chained or independently weaponized an improper certificate validation vulnerability alongside an arbitrary path traversal flaw. As a result, adversaries could bypass standard inspection routines or extract sensitive configuration files directly from internet-facing management gateways.
- Identified CVEs: CVE-2026-85102 (Improper Certificate Validation) and CVE-2026-93616 (Path Traversal)
- Attack Vector: Inadequate verification of cryptographic certificates combined with directory traversal sequences sent to the management web services.
- Source & Verification: CISA KEV Update Bulletin (September 22, 2026)
ShinyHunters Claims Breach of FBI Recruitment Infrastructure
On September 22, 2026, the extortion collective ShinyHunters claimed on a dark-web leak site that it breached FBI systems and exfiltrated sensitive data concerning personnel and job applicants. The bureau subsequently confirmed it was investigating unauthorized activity affecting its recruitment site, FBIJobs.gov, while working with third-party service providers. While the threat group claims to possess records covering thousands of agents, authorities have not officially verified the full scope or total victim count.
- Identified CVEs: No unique software CVE attributed; the group alleged access via an Oracle PeopleSoft environment and cloud-hosted assets.
- Attack Vector: Reported credential compromise or third-party web application intrusion; the FBI states the exact point of breach remains undetermined.
- Source & Verification: The Washington Post: Reporting on FBI Job Site Incident (September 23, 2026)
Weekly Mitigation & Patch Checklist
- [ ] Patch F5 BIG-IP APM: Update affected appliances running APM to the latest vendor-released hotfix to mitigate heap overflow exploits (CVE-2026-94127).
- [ ] Update Arista VeloCloud Instances: Apply security updates for VeloCloud Orchestrator immediately (CVE-2026-93952) and verify that management interfaces are not exposed to the public internet.
- [ ] Apply Check Point Security Fixes: Install the official patches addressing CVE-2026-85102 and CVE-2026-93616 across all Security Management servers.
- [ ] Audit Perimeter Access: Restrict administrative ports across all VPNs, firewalls, and SD-WAN orchestrators using strict IP allowlists and zero-trust network access policies.
- [ ] Scrutinize Third-Party HR/Recruiting Integrations: Review vendor access keys, multi-factor authentication enforcement, and audit logs for third-party recruitment or human capital management portals.
Conclusion & Emerging Trends
This week reinforces an ongoing trend: threat actors continue to bypass conventional endpoint defenses by targeting edge gateways and external enterprise portals directly. As attackers weaponize zero-days more rapidly, automated patch pipelines and perimeter exposure audits are mandatory.
Which of these edge device vulnerabilities poses the largest patching hurdle for your SecOps team this week?
TVA Cyber Services