Thursday, September 24, 2026 AboutContact
Tech

Three days to patch, and to prove nobody got in first

Twenty-six of the thirty-four vulnerabilities the United States cyber agency added to its known exploited catalogue in September carry a three-day patch deadline, against two of seventeen in January, and that tier demands forensic triage as well as a fix.

By Peter Lindqvist· September 23, 2026· 5 min read
Officials stand before a full-height wall tiled with the seal of the Cybersecurity and Infrastructure Security Agency at the agency's Executive Briefing Facility in Arlington, Virginia
Photo Courtesy: DHS photo by Lameen Witter · source

Federal civilian agencies running Check Point security gateways, Arista's VeloCloud Orchestrator or F5's BIG-IP APM have until 25 September 2026 to install a fix and to establish whether the machine had already been broken into. The Cybersecurity and Infrastructure Security Agency added four vulnerabilities in those products to its Known Exploited Vulnerabilities Catalog on 22 September 2026 and set the remediation date for all four at 25 September, three calendar days later.

The three days are the shorter half of the obligation. Under Binding Operational Directive 26-04, an entry in the top tier of the risk model requires an agency to remediate and, in the directive's own words, to "carry out a forensic triage of the asset to assess whether the system is compromised." Patching closes the door. Triage asks whether anyone walked through it before the lock was changed.

The four systems on the list

The catalogue entries, published in the agency's machine-readable feed at catalogue version 2026.09.22, name two Check Point flaws, one in Arista's VeloCloud Orchestrator and one in F5's BIG-IP APM. All four carry the same required action: apply mitigations per vendor instructions, ensuring compliance with the directive. All four are recorded with known ransomware campaign use listed as "Unknown". The catalogue held 1,721 entries in total at that version.

Severity comes from the vendors themselves, each acting as the assigning authority for its own products. Arista rated its flaw 10.0 on the version 3.1 scale, the maximum it allows, and 9.5 on version 4.0. Check Point rated both of its flaws 9.8 on version 3.1. F5 rated the BIG-IP flaw 9.8 on version 3.1 and 9.3 on version 4.0.

What the flaws do is set out in each vendor's own record. Check Point's CVE-2026-85102 is a failure to validate certificate trust during VPN negotiation on a Quantum Security Gateway, allowing unauthenticated remote code execution. Its CVE-2026-93616 combines directory traversal with file upload, letting an unauthenticated attacker place and run arbitrary scripts on a Management Server. Arista's flaw, in on-premises VeloCloud Orchestrator, "may allow a remote attacker to access privileged internal functionality and impact the VCO host"; the hosted and Dedicated versions were affected and have been patched. F5's is a heap-based buffer overflow that exists only where BIG-IP APM is configured as an OAuth Authorization Server with an access policy and an OAuth profile on a virtual server, and not where it runs as an OAuth Client or Resource Server.

Ordered before the analysis was finished

Check Point published its advisory on 22 September 2026 and says it observed exploitation of the certificate-validation flaw beginning 12 September 2026, against Spark customers globally, with traffic arriving through anonymisation infrastructure including VPN services and proxies. The second flaw, it says, was seen in "a handful of pinpointed attacks" on 23 July 2026, two months before the identifier was published. Arista's Security Advisory 0183 says of its own flaw: "This issue was discovered externally and is known to be actively exploited."

All four were still marked "Awaiting Analysis" at the National Vulnerability Database as of 23 September 2026. The agency had ordered a three-day federal patch on four vulnerabilities the national standards body had not finished analysing.

The directive that set the clock

BOD 26-04, "Prioritizing Security Updates Based on Risk", was issued on 10 June 2026 and supersedes two earlier directives: BOD 19-02 of 29 April 2019, on internet-accessible systems, and BOD 22-01 of 3 November 2021, which created the known exploited catalogue and gave every entry in it a fixed 15-day or 21-day deadline.

Table 1 of the new directive replaces those fixed windows with four tiers: three days for the highest risk, 15 days for high, 30 days for medium, and fix-on-upgrade for the rest. The top tier applies only where four conditions hold at once: that the asset is publicly exposed, that the vulnerability is in the catalogue, that it is automatable by an adversary, and that the technical impact is total control. The directive defines publicly exposed as "any agency-owned or agency-managed IT resource accessible to unauthenticated or untrusted entities via public networks, such as the internet, regardless of its physical or logical location." It does not define automatable by adversary at all, deferring instead to the definitions used by the agency's Vulnrichment programme.

"Known exploited vulnerabilities are a frequent attack vector for malicious cyber actors, including those backed by nation-states that aim to compromise U.S. critical infrastructure to steal sensitive information, disrupt operations, and undermine national security."

That line is from the directive itself. Its scope is every agency asset in a federal information system as defined in OMB Circular A-130, and it phases in three parts: immediate effect, 60 days to update vulnerability-management processes, and 180 days to remediate to the Table 1 timelines, tag all publicly accessible assets continuously, and give every asset on the federal dashboard an associated IP address.

What the catalogue's own numbers show

Counted from the published feed, the shape of the year is plain. Three-day entries by month in 2026 run 2 in January, 4 in February, 5 in March, 8 in April, 7 in May, 17 in June, 22 in July, 21 in August and 26 in September. Total additions over those months were 17, 28, 26, 31, 21, 23, 26, 31 and 34, or 237 additions to 22 September. Of September's 34, the 26 at three days and 8 at fourteen days account for the whole month; no other interval appears in it.

The catalogue holds 112 three-day entries in total, and the earliest was added on 27 January 2026. September's additions leaned heavily on network edge and security infrastructure: SonicWall, Citrix, Fortinet, three separate Cisco products, two MikroTik router flaws, Zyxel switches and ConnectWise remote-access software, alongside the four added on 22 September.

What is not established

Several things remain unknown. The affected and fixed BIG-IP APM version numbers could not be established from F5's own advisory, which serves only a JavaScript shell to a non-browser client, and the company's position on exploitation in the wild could not be read from it either. Check Point's exact fixed build numbers sit in support articles behind its customer portal. No source consulted names a threat actor, a state or a campaign behind any of the four, and nothing consulted says a federal agency was breached through them; the agency sets its deadlines on exposure, not on confirmed compromise.

The published directive names no individual signer, and it does not explain why the fixed 15-day and 21-day model was abandoned. Nor does anything primary explain why three-day deadlines appear in the feed from 27 January 2026, five months before the directive was issued. How many agencies run these four products, and how many will meet the 25 September deadline, is reported to the federal dashboard and is not public.