Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

CISA security alert graphic: active exploitation confirmed for Check Point, F5 BIG-IP and Arista gear

CISA Confirms Active Exploitation of Check Point, F5 and Arista Gear

The US government's cyber watchdog just told every federal department to patch four vulnerabilities and hunt for signs they've already been broken into. All four sit in gear plenty of Australian businesses run too: Check Point VPN gateways, F5's BIG-IP access manager, and Arista's SD-WAN orchestrator.

On 22 September, CISA added the four flaws to its Known Exploited Vulnerabilities catalog after confirming real attacks, giving federal agencies until 25 September to patch. Two are in Check Point's Security Gateway and management servers, one is a heap overflow in F5 BIG-IP Access Policy Manager allowing code execution with no login, and one hits Arista's VeloCloud Orchestrator, used to link offices and cloud. None need a username or password to exploit.

This is Check Point's second appearance on CISA's list this fortnight (we flagged the first round on 14 September), a pattern we see constantly in client environments: VPN gateways get configured once at rollout and never touched again, because patching means kicking remote staff offline. If you run Check Point, F5 or Arista gear, check your version against the vendor advisories today and apply the hotfix. Since these are confirmed under active exploitation, check your logs too, in case you've already been hit. Our cybersecurity team can run that check for you if you're not sure where to start.

Written by Michael Sacco, Head of Service Delivery, All IT Services. All IT is a Sydney-based managed IT provider supporting hospitality, not-for-profit and wealth management businesses across Australia.


Frequently Asked Questions

Four flaws under active attack: two in Check Point Security Gateway and management servers, one in F5 BIG-IP Access Policy Manager, and one in Arista's VeloCloud Orchestrator.
Not directly, but attackers are actively scanning for exactly this kind of internet-facing gear, so any VPN or remote-access tool you run deserves the same check.
It means CISA has confirmed the flaw is already being used in real attacks, so the advice shifts from "patch eventually" to "patch now and check for compromise."
Ask your IT provider to check if your edge devices are affected, get the vendor hotfix applied, and have someone review logs for signs of prior compromise.

Not sure what's exposed on your network edge?

All IT can check your firewalls, VPNs and remote-access gear against every current CISA advisory and get any gaps patched before they're found the hard way.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →