CISA Flags Actively Exploited Flaws in Check Point, Arista and F5 Products
The US Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively exploited by attackers. The affected products include multiple Check Point solutions (with a certificate validation flaw and a path traversal flaw), Arista's VeloCloud Orchestrator (an input validation flaw), and F5's BIG-IP APM (a heap-based buffer overflow).
These product types, security appliances, network orchestration tools and application delivery controllers, are widely used across businesses of all sizes, including many Australian organisations that rely on Check Point firewalls or F5 load balancers for network security. Vulnerabilities like these are common entry points for attackers because they often sit on the edge of a network, directly exposed to the internet.
While CISA's directive requiring urgent patching technically applies only to US federal agencies, the agency is urging all organisations globally to treat KEV-listed vulnerabilities as high priority. Any business running Check Point, Arista VeloCloud, or F5 BIG-IP products should check vendor advisories immediately and apply patches as soon as they are available.