การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Cyber Risk

CISA Expands Known Exploited Vulnerabilities Catalog with Four Critical Items

FORTSECURE GLOBAL· 2026-09-23🛰 CISA Cybersecurity Advisories
#Cyber Risk#CISA#Exploit#Network Security

CISA has officially added four widely exploited vulnerabilities affecting Check Point, Arista, and F5 products to its KEV catalog.

Urgent Threat Landscape Update

The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog, reflecting active exploitation in the wild. The newly added vulnerabilities include significant flaws in popular networking and security infrastructure:

  1. Check Point Products: Issues involving improper certificate validation (CVE-2026-85102) and path traversal (CVE-2026-93616).
  2. Arista VeloCloud Orchestrator: Improper input validation flaws (CVE-2026-93952).
  3. F5 BIG-IP APM: A heap-based buffer overflow vulnerability (CVE-2026-94127).

Because these vulnerabilities are currently being exploited, organizations using these technologies are at heightened risk of compromise. Attackers are likely using these vectors to gain unauthorized network access or execute arbitrary code.

Strategic Security Actions

To mitigate these risks, organizations must prioritize these updates immediately:

  • Catalog Synchronization: Cross-reference your IT hardware list against the CVEs listed in the CISA KEV catalog. If you use affected products from Check Point, Arista, or F5, prioritize them for immediate maintenance.
  • Update Infrastructure: Ensure that security appliances are running the most recent firmware versions that include official vendor patches.
  • Threat Hunting: Given that these are 'known exploited,' perform threat hunting activities within your environment to identify any signs of prior unauthorized access through these specific vectors.
  • Review Security Policies: Evaluate your patching cadence for edge devices and networking hardware to ensure that critical updates are deployed well within the organization's risk tolerance window.

แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Tue, 22 Sep 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: CISA Cybersecurity Advisories

เผยแพร่ครั้งแรก: Tue, 22 Sep 26 12:00:00 +0000

บทความต้นฉบับ: https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog