Check Point's management path traversal was being exploited on July 23. CISA put it on the Known Exploited Vulnerabilities list on September 22, alongside a second Check Point bug and F5's BIG-IP APM flaw, and gave federal agencies until September 25 to patch. Four days later, watchTowr said two unpatched remote code execution zero-days were being used against Citrix NetScaler ADC and Gateway. SonicWall's SMA1000 had already taken its third zero-day chain in a year.
That is a lot of front doors failing at once. We asked two practitioners who harden this gear for a living what to make of it. They agree on the diagnosis and the to-do list. They split hard on whether you should run these boxes yourself at all.
RelatedF5 BIG-IP and Check Point Zero-Days: What to Patch First
Why the gateway keeps being the target
Yezid Negash, founder and systems architect at TwinVault Technologies in Toronto, starts with a bad assumption. "The fundamental problem is treating edge appliances like F5, Check Point, and SonicWall as trusted, impenetrable fortresses," he said. "These gateways run complex management and authentication planes exposed directly to the public internet, so a single flaw becomes a single point of catastrophic failure."
He doesn't blame any one vendor for that. "That's not a flaw in any one vendor's code; it's what happens when you put pre-auth network services at the exact seam between 'trusted' and 'untrusted.'"
Hans Study, an independent network and security consultant and vCISO who has spent more than 15 years installing and hardening networks for government and utility sites in Canada and the US, reaches for a physical picture. "Think of them as the main gates to a facility," he said. "They face the internet by design, every remote user passes through them to get to the network and the resources inside, and they run on a locked-down operating system that we as the customer can't inspect or patch on our own schedule... we wait for the vendor. Once an attacker is through that gate they're inside the perimeter with a trusted IP and a pile of active sessions."
He doesn't think the category is inherently harder to secure. His complaint is about age. "The vendors have spent the better part of 20 years adding features onto the same appliance code, and the management side of these boxes was never built with the assumption that someone hostile would ever reach it."
The KEV list is a receipt, not an alarm
Both read the Check Point timeline the same way: two quiet months before the federal listing.
"When a flaw is being exploited for 2 months before it shows up on the KEV list, the main thing to take away is that the list is confirmation, not warning," Study said. "By the time CISA confirms something the attacks have already been running for weeks; the vendor advisory comes first and that is what should start the clock for your team."
Negash put it almost the same way. "Vendor advisories are a lagging indicator, not an early warning system," he said. "Any organization that only starts its incident response clock on the day a CVE drops has already lost two months."
Study also noted that Check Point's interim workaround, restricting management servers to trusted internal addresses, is how they should have been deployed all along. "Every one of those management servers should have been restricted to trusted internal addresses from the day it was built," he said.
Is three days realistic?
They read the deadline differently. Negash sees a forced choice. The three-day mandate "is right to demand urgency," he said, "but for gear running live production traffic that many teams can't take offline without a maintenance window, the deadline forces a choice between a rushed patch and a known, actively exploited hole, and neither is really a decision about security; it's a decision about which risk you're willing to own publicly."
Study thinks the technical part is easy and the organization is the bottleneck. "For the patch itself, yes. A hotfix on a gateway is an hour of work. What takes 3 weeks is the approval, the maintenance window, and the argument with the business about taking remote access down." His fix is procedural: an emergency change path for KEV entries, agreed with the business ahead of time, "with the maintenance window and the rollback plan already written down so the debate doesn't happen during the incident."
RelatedCitrix NetScaler Zero-Days CVE-2026-88771/88772: Patch Now
Where they split: cloud or keep the box
Negash thinks most organizations should hand the problem off. "Moving to cloud-delivered access doesn't remove the target; it moves patching and configuration liability onto a provider with the scale to respond in hours instead of weeks," he said, calling that "the right trade for most organizations without a team dedicated full-time to this hardware." Self-hosted appliances are still defensible in his view, "but only for teams that can genuinely commit to out-of-band management and same-day patch SLAs. If you can't promise that honestly, you're keeping it on-prem out of inertia, not strategy."
Study's client list pulls him the other way. "I do believe the age of on-premise is not dead, and for a lot of my clients it's the only option (airgapped sites, OT networks, anyone with data residency requirements can't route their access through someone else's cloud)," he said. "Moving to cloud-delivered access doesn't remove the appliance problem either, it just moves the appliance to the vendor who patches it on their timeline and lets you know afterward. You are trading control for speed of patching, and for a water plant or a courthouse, control usually wins."
His alternative is consolidation. "I've walked into sites running a VPN concentrator, a separate SSL gateway, a vendor remote access box for the building systems, and a NGFW with its own portal, each one patched by a different team on a different schedule," he said. "Consolidate those down to as few gateways as the site can justify and the patch problem gets smaller with them."
The split is narrower than it looks. Negash's test is whether you can honestly promise same-day patching. Study's clients have to make that promise, because the cloud isn't an option for them.
What to do this week
Neither of them put patching first. "The single most useful thing a team running F5, Check Point, or NetScaler should do this week isn't patching," Negash said. "It's assuming the box is already compromised." Study's version: "The patch does nothing about an attacker who is already in." Their combined list:
- Take admin interfaces off the internet. Study: find every F5, Check Point and NetScaler admin interface reachable from the internet "and take it off." Negash: lock management interfaces "down to isolated out-of-band networks."
- Check your F5 APM configuration. Confirm whether APM is running as an OAuth authorization server, "since that is the only configuration this flaw affects," Study said.
- Hunt back to July. Pull the last two months of logs and look for logins you don't recognize. On the Check Point side, Study noted, "that window goes back to July."
- Remove implicit trust. Negash: strip these gateways of implicit internal trust and "require zero-trust identity verification before any traffic reaches core systems."
- Then patch. "Patch after that, not instead of it," Negash said.
For NetScaler, which had no fix when we last reported, the first three items are most of what you can do. Our NetScaler zero-day post has the exposure controls; the F5 and Check Point breakdown covers patch order and the certificate subjects worth grepping for.
- OfficialCISA KEV alert, September 22, 2026 : the four-CVE addition.
- VendorF5 advisory K000162605 : CVE-2026-94127, affected versions and IoCs.
- VendorCheck Point security advisory : both CVEs and the July 23 start.
- ResearchRapid7 ETR on CVE-2026-94127 : technical breakdown.
- ReportBleepingComputer on the NetScaler zero-days : watchTowr's findings.
- BackgroundGENZ TECH: F5 BIG-IP and Check Point zero-days : patch order and indicators.
- BackgroundGENZ TECH: two unpatched NetScaler RCE zero-days : exposure controls while no fix exists.
- DataGENZ TECH CVE Watchlist : every actively exploited flaw we track.
Quotes gathered directly by GENZ TECH from sources who volunteered to comment on this story, with full attribution.
