$ techbeacon▋
CVE & Exploits

CISA Expands Known‑Exploited List to Include Flaws in Check Point, Arista VeloCloud and F5 BIG‑IP APM

CISA Expands Known‑Exploited List to Include Flaws in Check Point, Arista VeloCloud and F5 BIG‑IP APM

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced Tuesday that it has added three newly identified security weaknesses to its Known Exploited Vulnerabilities (KEV) catalog, covering products from Check Point, Arista Networks' VeloCloud Orchestrator, and F5 Networks' BIG‑IP Access Policy Manager.

The KEV catalog is a curated repository of vulnerabilities that CISA has confirmed are being actively leveraged by threat actors. By publishing the list, the agency aims to give federal agencies and the broader public‑sector community a clear, actionable signal about which software flaws pose an immediate risk and merit prompt remediation.

The latest entries involve a range of enterprise‑grade solutions. Check Point's security gateways, widely deployed for firewall and intrusion‑prevention functions, contain a flaw that could allow an attacker to bypass security controls. Arista's VeloCloud Orchestrator, a central management platform for software‑defined wide‑area networking, is flagged for a vulnerability that may enable unauthorized manipulation of network traffic. F5's BIG‑IP Access Policy Manager, a component used to enforce user authentication and access policies, also appears on the list due to a weakness that could be abused to gain elevated privileges.

Security analysts note that inclusion in the KEV catalog typically follows evidence of real‑world exploitation, meaning that malicious actors have already demonstrated the ability to weaponize these bugs. Organizations that rely on any of the affected products are therefore urged to treat the findings as high priority, especially given the critical role these technologies play in protecting corporate and government networks.

CISA’s advisory advises immediate verification of patch status and, where patches are unavailable, the implementation of recommended mitigations such as temporary configuration changes, network segmentation, or heightened monitoring for suspicious activity. Both Check Point and F5 have issued security bulletins outlining remediation steps, while Arista has released an advisory encouraging customers to apply forthcoming updates.

The agency emphasizes that the KEV catalog will continue to evolve as new threats emerge, underscoring the importance of ongoing vulnerability management and information sharing across the public and private sectors. Stakeholders are encouraged to regularly consult CISA’s portal to stay informed about additional vulnerabilities that may be added in the coming weeks.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related