CISA gives agencies three days to patch four flaws
CISA has added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog and given US federal agencies until Friday to patch them.

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog on Tuesday, a list reserved for flaws that attackers are already using. Every entry carries a remediation deadline of 25 September for federal civilian agencies, three days after publication, and the catalog itself now holds 1,721 entries.
What went on the list
The highest scores belong to Check Point. CVE-2026-93616 carries a CVSS rating of 9.8 for a path traversal flaw in Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent, which CISA says lets an unauthenticated attacker upload and execute arbitrary scripts. The second Check Point issue, CVE-2026-85102, also rated 9.8, is an improper certificate validation flaw during VPN negotiation in Security Gateway and Spark Firewall when site-to-site or remote access VPN is in use, giving an unauthenticated attacker a route to running code on the gateway. Its NVD record has been public since 9 September, so the catalog entry is the first signal that it is being exploited rather than merely fixed.
Arista’s CVE-2026-93952, rated 9.5, is an input validation failure in the on-premises VeloCloud Orchestrator that CISA says may let a remote attacker reach privileged internal functionality and affect the orchestrator host, putting the confidentiality, integrity and availability of the orchestrator and the data it manages at risk. F5’s CVE-2026-94127, rated 9.3, is a heap-based buffer overflow in BIG-IP APM that appears when an access policy and an OAuth profile are configured on a virtual server, and it can be reached without authenticating. CISA points administrators at a vendor-supplied iRule as a temporary mitigation so they can carry out forensic triage before installing the final patch.
Why the deadline is the story
CISA’s entry for each of the four requires forensic triage, which is the catalog’s way of saying that a patched appliance is not the same as a clean one, and that administrators should look for signs of intrusions that predate the fix. All four entries list known ransomware campaign use as unknown, so the catalog confirms exploitation without naming who is doing it. The three-day deadline reflects the risk-based approach set out in binding operational directive 26-04, which replaced blanket patch windows with per-flaw decisions based on exposure.
Our opinion
Look at what got listed this week: a VPN gateway, a load balancer’s access policy engine, a cloud orchestrator and a security management server. None of them is a laptop, and all of them are the sort of appliance that sits on the internet, holds the keys to everything behind it and gets patched twice a year by whoever drew the short straw. That is the pattern worth taking from this list. The single most useful line in each CISA entry is not the CVSS score but the forensic triage instruction, because it concedes that for some organisations the compromise happened months before the patch existed. If you run any of these four products, the patch is the easy half of Tuesday’s work.