CISA Flags CVE-2026-85102 Security Bypass in Check Point, Arista, F5 Products
High · Security Affairs ·
CISA KEV · Exploited
Key points
- CISA added CVE-2026-85102 to its KEV catalog due to active exploitation.
- Unauthenticated attackers can bypass security checks.
- Affected products include VeloCloud Orchestrator and BIG-IP APM.
- Vendors involved: Check Point, Arista, F5.
- No scale or timeline details provided.
CVE-2026-85102, a just-disclosed security weakness, now appears in the Known Exploited Vulnerabilities list maintained by the Cybersecurity and Infrastructure Security Agency. This designation signals that the vulnerability is being actively exploited in the wild. The issue allows an attacker who has not authenticated to circumvent security checks, potentially gaining unauthorized access to affected systems.
The flaw impacts products from several vendors: Check Point, Arista, and F5. Specific products named include VeloCloud Orchestrator and BIG-IP APM. Organizations running these solutions should treat the vulnerability as high priority. Because the bypass requires no credentials, the barrier to exploitation is low, making rapid remediation essential.
Why does this matter? A security bypass that grants unauthenticated access can lead to data exposure, lateral movement, or full compromise of the affected appliance. The KEV listing means federal agencies must patch within a set timeframe, but private sector entities should also act urgently. The exact number of affected systems and the timeline of exploitation are not specified in current advisories.
Context: The KEV catalog is an authoritative list of vulnerabilities that have been exploited. Inclusion often triggers binding operational directives for U.S. federal agencies. For K-12 IT teams, this is a reminder to inventory internet-facing management interfaces and ensure they are not exposed unnecessarily.
What to watch: Monitor vendor advisories from Check Point, Arista, and F5 for patches and mitigation guidance. Since no scale or dates are provided, assume active scanning and exploitation. Prioritize patching VeloCloud Orchestrator and BIG-IP APM, and review logs for anomalous access attempts.
What to do now
- Immediately inventory all instances of VeloCloud Orchestrator and BIG-IP APM, along with Check Point, Arista, and F5 products.
- Apply vendor-supplied patches or hotfixes for CVE-2026-85102 as soon as they are available.
- If patching is not possible, disable or restrict access to affected management interfaces from the public internet.
- Enable and review authentication logs for signs of unauthenticated access or security check bypass attempts.
- Enforce multi-factor authentication on all administrative access to affected systems.
- Subscribe to CISA's KEV catalog updates and vendor security advisories for ongoing guidance.
- Conduct a compromise assessment if you detect suspicious activity, and isolate affected devices.
CVE references
- CVE-2026-85102
Original source
Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.