← Field notesExploited this week · 24 Sep 2026

Eight added to KEV last week. Five are network appliances.

Eight vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalogue between 18 and 22 September. Five of them are network or security appliances.

  1. Check Point, multiple products, two entries
  2. F5 BIG-IP APM
  3. Arista VeloCloud Orchestrator
  4. Zyxel GS1900 series switches

The other three are in the Linux kernel.

CISA gave all eight its shortest deadline, three days, for US federal agencies.

It is the second week running that network appliances lead the list. NCSC said on 27 August that disruptive activity is being driven by internet-exposed systems and edge devices. The catalogue keeps agreeing.

Three questions for this week.

  1. Do you have a list of every appliance that terminates remote access or manages your network? Not the ones in the design document. The ones that are switched on.
  2. Is the management interface of each one reachable from the internet? If it is, that is the first thing to change.
  3. Who is told when a vendor you run appears in the catalogue? If the answer is nobody in particular, it will be found late.

Sources: CISA Known Exploited Vulnerabilities catalogue v2026.09.23 (entries dated 18 to 22 Sep 2026). NCSC, 27 Aug 2026, Disruptive cyber activity highlights risk from internet-exposed systems and edge devices: https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices

Written by Ben Brand, Velinor. The method behind these notes runs as Picket by Velinor.

More notes