CISA Confirms Active Exploitation of Check Point, F5 and Arista Gear
The US government's cyber watchdog just told every federal department to patch four vulnerabilities and hunt for signs they've already been broken into. All four sit in gear plenty of Australian businesses run too: Check Point VPN gateways, F5's BIG-IP access manager, and Arista's SD-WAN orchestrator.
On 22 September, CISA added the four flaws to its Known Exploited Vulnerabilities catalog after confirming real attacks, giving federal agencies until 25 September to patch. Two are in Check Point's Security Gateway and management servers, one is a heap overflow in F5 BIG-IP Access Policy Manager allowing code execution with no login, and one hits Arista's VeloCloud Orchestrator, used to link offices and cloud. None need a username or password to exploit.
This is Check Point's second appearance on CISA's list this fortnight (we flagged the first round on 14 September), a pattern we see constantly in client environments: VPN gateways get configured once at rollout and never touched again, because patching means kicking remote staff offline. If you run Check Point, F5 or Arista gear, check your version against the vendor advisories today and apply the hotfix. Since these are confirmed under active exploitation, check your logs too, in case you've already been hit. Our cybersecurity team can run that check for you if you're not sure where to start.
Written by Michael Sacco, Head of Service Delivery, All IT Services. All IT is a Sydney-based managed IT provider supporting hospitality, not-for-profit and wealth management businesses across Australia.
Frequently Asked Questions
Not sure what's exposed on your network edge?
All IT can check your firewalls, VPNs and remote-access gear against every current CISA advisory and get any gaps patched before they're found the hard way.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
