[{"id":"EUVD-2026-84296","enisaUuid":"9a0f96cd-b241-3325-bac6-403585d25627","description":"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.\n\nHosted, including Dedicated, versions of VCO were impacted and have already been patched.","datePublished":"Sep 22, 2026, 7:37:24 AM","dateUpdated":"Sep 23, 2026, 3:55:40 AM","baseScore":9.5,"baseScoreVersion":"4.0","baseScoreVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","references":"https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183\n","aliases":"GHSA-fqhw-f6hf-cq3w\nCVE-2026-93952\n","assigner":"Arista","epss":0.42,"exploitedSince":"Sep 22, 2026, 12:00:00 AM","enisaIdVendor":[{"id":"13316001-30d9-3bec-8d94-9ede59e5655c","vendor":{"name":"Arista Networks"}}]},{"id":"EUVD-2026-75009","enisaUuid":"daeb886f-e96a-376f-9a2e-6df28375ff82","description":"Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.","datePublished":"Sep 9, 2026, 1:00:31 PM","dateUpdated":"Sep 23, 2026, 3:55:34 AM","baseScore":9.8,"baseScoreVersion":"3.1","baseScoreVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":"https://support.checkpoint.com/results/sk/sk1000117\n","aliases":"GHSA-3fvr-5gg9-225m\nCVE-2026-85102\n","assigner":"checkpoint","epss":0.33,"exploitedSince":"Sep 22, 2026, 12:00:00 AM","enisaIdVendor":[{"id":"8ac36027-c694-3480-a2a8-e5078145b37c","vendor":{"name":"checkpoint"}}]},{"id":"EUVD-2026-84375","enisaUuid":"7582643c-b06d-322f-84da-2ebfedc224fd","description":"A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.","datePublished":"Sep 22, 2026, 12:59:01 PM","dateUpdated":"Sep 23, 2026, 3:55:59 AM","baseScore":9.8,"baseScoreVersion":"3.1","baseScoreVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":"https://support.checkpoint.com/results/sk/sk1000171\n","aliases":"GHSA-x5gq-4cxx-rf2r\nCVE-2026-93616\n","assigner":"checkpoint","epss":0.0,"exploitedSince":"Sep 22, 2026, 12:00:00 AM","enisaIdVendor":[{"id":"19af7400-908a-38b4-9e35-770f85ef6e67","vendor":{"name":"checkpoint"}}]},{"id":"EUVD-2026-84427","enisaUuid":"8ce26194-5a43-37c8-a5fe-fc185e068b86","description":"When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.\n\nImpact:\nThis vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.\n\n \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.","datePublished":"Sep 22, 2026, 2:17:42 PM","dateUpdated":"Sep 23, 2026, 3:55:44 AM","baseScore":9.3,"baseScoreVersion":"4.0","baseScoreVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","references":"https://my.f5.com/manage/s/article/K000162605\n","aliases":"CVE-2026-94127\nGHSA-qppv-6jrg-hxq4\n","assigner":"f5","epss":0.0,"exploitedSince":"Sep 22, 2026, 12:00:00 AM","enisaIdVendor":[{"id":"b42038ce-4d4d-3900-8da2-9d9ccead5d8a","vendor":{"name":"F5"}}]}]