F5 and Arista ship fixes for actively exploited zero-day flaws
Admins of BIG-IP APM and VeloCloud Orchestrator must move quickly as both zero-days are under active attack and already flagged by CISA.
F5 and Arista have both shipped patches for critical zero-day vulnerabilities in widely deployed network access and SD-WAN management products that are already under active exploitation. F5 fixed a remote code execution bug in BIG-IP APM when an access policy and OAuth profile are configured on a virtual server, and is providing an iRule-based mitigation for customers that cannot patch immediately. CISA added F5’s CVE-2026-94127 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to remediate it by Friday, underscoring the urgency for any operator running BIG-IP APM. Arista addressed CVE-2026-93952, an improper input validation flaw in on-prem VeloCloud Orchestrator allowing unauthenticated attackers with network access and a public edge certificate to reach privileged internal functionality, and has already updated hosted VCO instances on specific 5.2.x and 6.4.x versions. CISA likewise added Arista’s CVE-2026-93952 to the KEV catalog and U.S. agencies must fix it by Friday, while Arista is telling admins to restrict VCO web access, hunt for suspicious log patterns and outbound traffic, and block two specific IPs linked to ongoing exploitation.
Why it matters
Operators running BIG-IP APM and on‑prem VeloCloud Orchestrator now face confirmed, actively exploited flaws that enable remote code execution or privileged access without user credentials. For BIG-IP APM, thousands of internet-facing instances are potentially exposed, and U.S. federal agencies are under a deadline to secure affected systems or apply F5’s iRule mitigation. Arista customers with vulnerable VCO setups must patch or lock down web access, since attackers need only network reachability and a public edge certificate to abuse the bug.
Signal or noise?
Does this story matter, or is it hype? Decide before you see what everyone else thinks.