The 5-Minute Cyber Brief: September 23, 2026

By George Bailey   Published: 09/22/26   Updated: 09/22/26   2 min read

Published: 09/23/26

Wednesday’s clock is a three-day federal sprint on the security edge — plus one due today. CISA added Check Point’s VPN gateway RCE and management zero-day to KEV with a September 25 due date, the same Friday deadline as F5’s unauth BIG-IP APM/OAuth RCE and Arista’s CVSS 10 on-prem VeloCloud Orchestrator. Chromium’s in-the-wild V8 write is due September 23.

Lead Story

Check Point: VPN Gateway + Management Plane — Due Friday

Two CVSS 9.8s, both unauth, both KEV: improper VPN certificate validation on the gateway (already sprayed at Spark customers) and a pre-auth management path traversal zero-day. Federal due September 25; forensic triage required. LivePatch alone does not fix the management bug.

Why it matters: Gateway RCE is the front door; management RCE is the master key.

Read more on CyberExperts: Read the analysis

Also Worth Your Attention

F5 BIG-IP APM: Unauth OAuth RCE — Due Friday

Heap overflow when a VIP has both APM and an OAuth profile. Unauth data-plane RCE; Appliance mode still vulnerable. Hotfixes and an interim iRule are out; KEV due September 25.

Why it matters: That VIP is often your SSO front door.

Read more on CyberExperts: Read more

Arista VeloCloud: Orchestrator CVSS 10 — Due Friday

On-prem VCO improper input validation, actively exploited, CVSS 10. Hosted is patched; on-prem needs 5.2.3.16+ or 6.4.2.8+ and an IoC hunt for a known backdoor hash.

Why it matters: Own the orchestrator, inherit the SD-WAN fabric.

Read more on CyberExperts: Read more

Chromium V8: Sandbox Code Exec — Due Today

In-the-wild V8 out-of-bounds write. Chrome 153.0.8010.36/.37 fixes it. Federal KEV due is September 23 — verify Edge and other Chromium browsers too.

Why it matters: Due-today means prove the build number, not the intent.

Read more on CyberExperts: Read the analysis

Go Deeper

Identity & access: IAM library · Tools & playbooks: Cybersecurity Tools · Subscribe: Daily Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.