Weekly Security Roundup: September 22 to 28, 2026

Part of our weekly series. Previous: Roundup for September 8 to 21, 2026.

Sherlock Forensics security roundup for September 22 to 28, 2026. CISA added six actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, all affecting edge, VPN or management appliances: F5 BIG-IP APM, Check Point Security Gateway and Management, Arista VeloCloud Orchestrator, WSO2 and Adobe Commerce. Separately, watchTowr disclosed two Citrix NetScaler zero-days found during a forensic investigation, patched by Citrix on September 27. All eight flaws scored 9.0 or higher, all are exploited in the wild and all have fixes.

Every vulnerability on this list has three things in common. Each one scored 9.0 or higher. Each one is being exploited in the wild right now. And each one already has a patch. That combination is the whole story of the week: the fixes exist, the attackers are moving faster than the patch cycles and the targets are the boxes that sit at the edge of the network.

An IT team reads a list like this as a patch queue. An examiner reads it differently. Every actively exploited flaw on an internet-facing appliance is a future incident-response case, and the appliance that got hit is usually the same box that holds the logs proving how. Patch too fast, reimage without a capture, and you close the hole and erase the evidence in the same move. That is not a hypothetical trade-off. It is the single most common way a defensible investigation dies before it starts, and it happens in the first hour, done by people trying to help. Here is the week, and what it means before you hit update.

Six flaws added to CISA KEV

The Cybersecurity and Infrastructure Security Agency added six vulnerabilities to its Known Exploited Vulnerabilities catalog this week, across two alert days. When a CVE lands in KEV it is not theoretical. It means exploitation is confirmed and, for federal agencies, the clock on a mandatory remediation deadline has started. For everyone else it is the clearest signal you will get that a flaw is being used against real targets today.

CVE-2026-94127, F5 BIG-IP APM, CVSS 9.8. A heap-based buffer overflow in the Access Policy Manager allows an unauthenticated attacker to run code remotely. It affects BIG-IP APM 17.1.0 through 17.1.3, 17.5.0 through 17.5.1 and 21.1.0 when the access policy uses an OAuth authorization server profile. It was added to KEV on September 22 and was exploited as a zero-day before the fix existed. F5 has shipped engineering hotfixes + an iRule mitigation. This is an unauthenticated remote code execution on a device that terminates VPN and application access for the whole organisation, which is about as high-value a foothold as an attacker can ask for.

CVE-2026-93616, Check Point Security Management, CVSS 9.8. A pre-authentication path traversal in the management plane lets an attacker execute a script from an arbitrary path or load an arbitrary Java class, with no credentials. It affects R82.20, R82.10 at hotfix 44 or lower, R82 at hotfix 126 or lower + earlier releases, across the Management Server, Multi-Domain, Log Server and SmartEvent roles. Check Point released the fix on September 22, the same day it hit KEV, and reports a handful of targeted attacks. The management server is where your firewall policy and your log data live, so a pre-auth compromise there is both an intrusion and a threat to the records of the intrusion.

CVE-2026-85102, Check Point Security Gateway, CVSS 9.8. Improper certificate validation during VPN negotiation allows unauthenticated remote code execution against the gateway and Spark firewall lines, affecting R81 through the R82.00.X branches. One flag worth stating plainly: the patch and disclosure here landed on September 9, before this reporting window. What is new this week is the KEV listing, added September 22, with exploitation observed in the wild since around September 12. If you patched on September 9 you are covered. If you deferred it, the KEV listing is your signal that the window for deferring is closed.

CVE-2026-93952, Arista VeloCloud Orchestrator, CVSS 10.0. Improper input validation in the on-premises VeloCloud Orchestrator lets a remote attacker reach privileged internal functionality and affect the orchestrator host itself. It scores a full 10.0 on CVSS 3.1 (9.5 on CVSS 4.0) and affects on-prem builds 5.2.0 through 7.0.0.2, with hosted instances already patched. Added to KEV on September 22. Upgrade the on-prem build. An orchestrator sits above the network fabric it manages, so a compromise there is not one device, it is the control plane for many, and the blast radius in an investigation is every branch and tunnel it touches.

CVE-2026-5430, WSO2, CVSS 10.0. A JWT signature-validation flaw where a token signed with an unsupported algorithm is incorrectly accepted, producing an authentication bypass and administrator account takeover. It spans API Manager, the API Control Plane, Traffic Manager and Universal Gateway across multiple release lines. Added to KEV on September 24. Note that NVD first published this one on August 6, so the disclosure is older, the KEV addition is what is new. A full 10.0, and an auth bypass is the quietest kind of breach because the attacker arrives looking like a legitimate admin.

CVE-2026-71362, Adobe Commerce and Magento Open Source, CVSS 9.1. An incorrect-authorization flaw allows privilege escalation to sensitive resources across Adobe Commerce, Magento Open Source and Commerce B2B. Adobe shipped patched builds in August, and the CVE was added to KEV on September 24. As with WSO2, the disclosure predates this week, the active-exploitation confirmation is what moved it onto the list. For a storefront, privilege escalation is a direct line to customer and payment data.

Two Citrix NetScaler zero-days, found during a forensic investigation

The other headline this week did not come from a scanner or a bug bounty. On September 26 the research team at watchTowr disclosed a pair of NetScaler zero-days they uncovered while doing incident-response work, which is exactly how real intrusions surface. Citrix published bulletin CTX697096 and shipped fixes on September 27.

CVE-2026-88771, Citrix NetScaler ADC and Gateway, CVSS 9.5. Improper input validation allows unauthenticated arbitrary command execution. Actively exploited in the wild, vendor confirmed. Fixed builds shipped September 27.

CVE-2026-88772, Citrix NetScaler ADC and Gateway, CVSS 9.5. A memory overflow that allows remote code execution or denial of service when DTLS is enabled. Also actively exploited, also fixed on September 27.

NetScaler has been a favourite target for two years running, and the pattern holds: an edge device, an unauthenticated flaw, exploitation in the wild before most defenders knew the CVE existed. That these were found mid-investigation is the point we keep making. By the time a flaw like this is named, someone has already used it, and the proof is sitting in the appliance logs until it is overwritten.

By the numbers

  • Six vulnerabilities added to CISA KEV this reporting window (F5, Check Point twice, Arista, WSO2, Adobe)
  • Eight critical flaws covered here, every one scoring 9.0 or higher
  • Two scoring a perfect 10.0 (Arista on CVSS 3.1, WSO2)
  • Patch available for all eight
  • Active exploitation confirmed for all eight, by KEV listing or vendor confirmation

What this means for your evidence

Look at where these flaws live. F5 BIG-IP, Check Point gateways + management, Arista VeloCloud, Citrix NetScaler. Every one is an edge, VPN or management appliance, and that is not a coincidence. The network perimeter is where attackers get in, and it is also where the evidence of how they got in is recorded. Those two facts collide the moment you start remediating.

When an actively exploited flaw is confirmed in your stack, the appliance is not just a patch target, it is a potential crime scene. The standard reflex, patch and reboot or reimage and restore, is the fastest way to destroy volatile memory, session tables and local logs that would have shown you whether you were breached and what the attacker touched. The forensic discipline is simple to state and easy to skip under pressure: preserve before you remediate. Capture volatile data and pull the logs off the box before the fix or the rebuild overwrites them, and hash what you collect so it holds up later.

The Check Point Security Gateway flaw is a VPN box, which means the authentication and session logs on it are the record of who connected and when. The auth-bypass flaws in WSO2 and Adobe Commerce leave an account-takeover trail, where a legitimate-looking admin session is the intrusion. Email-adjacent compromises reach the mailbox, and a preserved PST or OST archive examined read-only is the fixed reference an investigation can hash and reproduce, which is what Sherlock Forensics PST Viewer is built to do. Where a mobile device is in scope, consent-based acquisition that documents its own limits is what survives a challenge, the ground Sherlock Forensics Android Acquirer and Sherlock Forensics iPhone Analyzer are built on.

There is a second reason to preserve first, beyond simply knowing what happened. If the intrusion ever becomes a legal matter, an insurance claim, a regulator's question or litigation, the value of what you collected depends on how you collected it. Evidence pulled off a live appliance in a panic, with no hash and no record of who touched it when, is easy for the other side to challenge and hard to rely on. Evidence captured read-only, hashed at collection and logged with a clean chain of custody holds up. The difference is not the data, it is the process, and the process has to start before the cleanup, because you cannot re-capture volatile state once it is gone.

None of this changes the patch timeline. Patch fast, these are all being exploited now. It changes the ninety seconds before you patch: decide whether this box needs to be captured first, and if the answer is maybe, bring in someone who does this for a living before the evidence is gone. Sherlock Forensics has done exactly this kind of edge-appliance intrusion work since 2006, and the Citrix pair this week is a reminder that the deepest findings often come out of the investigation, not the advisory.

What to do this week

  1. Cross-check your inventory against the eight CVEs above. Edge and VPN appliances first, they are the ones under active fire.
  2. For any confirmed-exploited flaw in your environment, treat the affected box as a possible intrusion. Preserve volatile data + logs before you patch or reimage.
  3. Apply the vendor fixes. All eight have patches: F5 hotfixes, Check Point fixes from September 22 and September 9, Arista on-prem upgrades, WSO2 update levels, Adobe August builds, Citrix builds from September 27.
  4. Hunt, do not just patch. KEV listing means exploitation is confirmed, so assume attempts against your perimeter and review the logs while they still exist.
  5. If you find signs of compromise, stop and preserve. A defensible investigation starts before the cleanup, not after.

Frequently asked questions

What were the most exploited vulnerabilities the week of September 22, 2026?

Six flaws were added to the CISA Known Exploited Vulnerabilities catalog: F5 BIG-IP APM (CVE-2026-94127), two Check Point flaws (CVE-2026-93616 and CVE-2026-85102), Arista VeloCloud Orchestrator (CVE-2026-93952), WSO2 (CVE-2026-5430) and Adobe Commerce (CVE-2026-71362). Two Citrix NetScaler zero-days (CVE-2026-88771 and CVE-2026-88772) were also disclosed and confirmed exploited. All eight scored 9.0 or higher and all have patches.

Which CVEs were added to CISA KEV the week of September 22, 2026?

Six. On September 22: F5 BIG-IP APM (CVE-2026-94127), Check Point Security Management (CVE-2026-93616), Check Point Security Gateway (CVE-2026-85102) and Arista VeloCloud Orchestrator (CVE-2026-93952). On September 24: WSO2 (CVE-2026-5430) and Adobe Commerce (CVE-2026-71362).

How should an incident responder handle an actively exploited CVE on an edge appliance?

Treat the appliance as a potential crime scene, not just a patch target. Before you patch, reboot or reimage, capture volatile memory, session data and local logs, because those are overwritten by remediation. Hash what you collect so it is verifiable later. Then apply the vendor fix. Preserving before remediating is the difference between knowing what happened and guessing.

Does patching a vulnerability destroy forensic evidence?

It can. Patching, rebooting and especially reimaging or restoring from backup overwrite the volatile data, memory and local logs that show whether a device was compromised and what an attacker did. If a flaw is actively exploited and present in your environment, preserve the affected system before remediation, or you may close the hole and erase the proof at the same time.

Why do so many exploited vulnerabilities target VPN and edge devices?

Edge, VPN and management appliances are internet-facing and sit at the trust boundary, so a single unauthenticated flaw hands an attacker a foothold into the whole network. This week every KEV addition affected that class of device. They are also where the connection and authentication logs live, which makes them both the way in and the record of it.

Sources

  • CISA, four Known Exploited Vulnerabilities added (Sept 22, 2026): cisa.gov
  • CISA, two Known Exploited Vulnerabilities added (Sept 24, 2026): cisa.gov
  • CISA Known Exploited Vulnerabilities Catalog: cisa.gov
  • F5 security advisory K000162605 (CVE-2026-94127): my.f5.com
  • Check Point advisory (CVE-2026-93616 and CVE-2026-85102): blog.checkpoint.com
  • NVD, CVE-2026-93952 (Arista VeloCloud Orchestrator): nvd.nist.gov
  • NVD, CVE-2026-5430 (WSO2): nvd.nist.gov
  • NVD, CVE-2026-71362 (Adobe Commerce and Magento): nvd.nist.gov
  • watchTowr, Citrix NetScaler zero-day FAQ (CVE-2026-88771, CVE-2026-88772): watchtowr.com

Previous in this series: Weekly Security Roundup: September 8 to 21, 2026.