Patch Analysis & Exploitation Timeline: A Check Point Flaw Exploited 61 Days Before Its Fix Leads CISA's September 22, 2026 KEV Additions
Four CVEs entered CISA’s KEV catalog on September 22, 2026, but their exploitation histories differ. A Check Point management zero-day had documented attacks at least 61 days before its fix, while VPN exploitation attempts were observed three days after an initial patch. This analysis separates attack observations, patch evidence, and catalog timing.
Dataset Summary
| Field | Value | Interpretation |
|---|---|---|
| Reporting Period | September 22, 2026 KEV additions | The supporting chronology spans July 23–September 22, 2026. Sources were reviewed on September 28; the recorded remediation deadline was September 25. |
| Data Sources | CISA KEV; official CVE records; product security advisories | Public primary sources provide the additional dates, affected configurations, and remediation details. |
| Total CVEs Analyzed | 4 | CVE-2026-93952, CVE-2026-94127, CVE-2026-93616, and CVE-2026-85102. No additional CVEs enter the calculations. |
| Average Disclosure-to-Patch Gap | Full-cohort value unavailable | Using CVE publication as the disclosure field, the two Check Point cases with explicitly dated initial fixes each yield 0 calendar days. Their mean and median are 0; this is a two-record subset, not a four-CVE result. |
| Average Patch-to-Exploitation Gap | Unavailable | The true first-exploitation date is not established for every entry. A dated attack observation, a publication date, and KEV inclusion are not interchangeable. |
| Average / Median CVE-Publication-to-KEV Gap | 3.25 days / 0 days | All four records have confirmed publication and catalog dates. Three entered KEV on their CVE publication date; the VPN certificate-validation CVE entered 13 days later. |
| Shortest / Longest Publication-to-KEV Gap | 0 days / 13 days | CVE-2026-93952, CVE-2026-94127, and CVE-2026-93616 tie at 0. CVE-2026-85102 accounts for the 13-day maximum. |
| Documented Pre-Patch Exploitation Lead | CVE-2026-93616: at least 61 days | A July 23 attack observation predates the September 22 fix. This is a minimum lead relative to the documented fix, not proof of continuous attacks throughout the interval. |
| Post-Patch Exploitation-Attempt Observation | CVE-2026-85102: 3 days after the initial fix | A wave of VPN exploitation attempts was observed from September 12, following the September 9 fix. This does not prove there were no earlier attempts or compromises. |
| KEV-to-Due-Date Interval | 3 calendar days for all four | September 22 to September 25. Every entry records forensic triage as “Yes” and known ransomware campaign use as “Unknown.” |
Sourcing and Methodology Note
The four-CVE selection is corroborated by CISA’s CISA Adds Four Known Exploited Vulnerabilities to Catalog alert of September 22, 2026. The KEV catalog, version 2026.09.27, supplies catalog dates and response fields; the four official CVE Program records supply publication dates, weakness classifications, and version-labeled severity scores.
Technical and patch references are Security Advisory 0183; F5 articles K000162605 and K000163302; and Check Point articles sk1000117 and sk1000171. The September 22 Check Point exploitation advisory supplies the dated attack observations and initial fix dates. Official security guidance AL26-022 corroborates F5 hotfix availability by September 22. MITRE ATT&CK T1046 supports the limited behavioral mapping below.
Sources were reviewed on September 28, 2026. Calendar-day calculations and operational interpretation are SecPod’s analytical layer. “Known exploitation” means an explicit exploitation report or KEV inclusion; neither alone establishes mass exploitation. Missing first-attack or exact release dates remain unavailable, and partial-sample results are labeled.
Introduction
One vulnerability in the September 22 KEV additions had documented attacks at least 61 days before its fix. For CVE-2026-93616, the management-server attack observation and the patch date establish a substantial pre-patch lead. Yet its CVE publication and KEV addition occurred on the same calendar day.
This contrast is the central finding: same-day CVE publication and KEV addition can coexist with a much older exploitation history. The four-entry dataset also includes a VPN case with dated post-patch exploitation attempts, alongside VeloCloud and F5 cases whose exact first-attack dates remain unconfirmed.
Background and Context
The dataset spans orchestration, access-policy processing, management servers, and VPN gateways. These are different exposure paths, not four interchangeable instances of the same vulnerability.
VeloCloud exposure depends on certificate-based Edge-to-Orchestrator authentication, access to the public portion of an Edge authentication certificate, and network reachability to the VCO web interface. Tenant or operator credentials are not required.
For F5, the affected configuration is BIG-IP APM acting as an OAuth Authorization Server, with the relevant access policy and OAuth profile on a virtual server. OAuth Client or Resource Server use alone, without an authorization-server profile, is excluded by the CVE description. The exposure is in the data plane, not the control plane.
The Check Point entries must also remain separate. CVE-2026-93616 concerns management and logging products; CVE-2026-85102 concerns VPN certificate validation on Security Gateway and Spark Firewall. The VPN advisory excludes gateways participating only in pre-shared-key encryption communities; mixed configurations and certificate-enabled communities require separate assessment.
Gap Calculation Methodology
D is the UTC calendar date in the CVE record’s datePublished field. P is an explicitly dated initial fix release. B is a dated attack observation. E is the true first-exploitation date, which may precede B. K and R are KEV’s addition and due dates.
CVE-Publication-to-Patch Gap = P − D
CVE-Publication-to-KEV Gap = K − D
Patch-to-KEV Gap = K − P
Patch-to-Observed-Attack Interval = B − P
Minimum Pre-Patch Lead = P − B, when B precedes P
Actual Patch-to-First-Exploitation Gap = E − P
Calculations subtract calendar dates without inclusive counting. A same-day result does not establish the order of events within that day. CVE publication is used consistently for D; a knowledge-base article’s creation or modification timestamp is not silently substituted for public disclosure.
The Check Point initial fix dates are explicitly documented. F5 hotfixes are corroborated as available by September 22, but that does not independently establish their earliest release date. VeloCloud’s reviewed advisory identifies fixed versions without separately dating each release. Those two cases are excluded from exact P-based averages, not from the four-CVE dataset.
P describes the initial documented remedy, not the release date of every later hotfix, build, or coverage enhancement. B is an observation, not proof of E. Accordingly, the article does not convert bounded or missing dates into an exact four-CVE exploitation average.
Patch Timeline & Exploitation Gap Analysis
The complete publication-to-KEV distribution is [0, 0, 0, 13] calendar days. Its mean is 3.25 days, while its median is 0 days. The mean exceeds the median because one record has a materially longer interval; it does not imply that any individual CVE took 3.25 days to enter the catalog.
| Metric | Usable Records | Mean / Median | Interpretation |
|---|---|---|---|
| CVE publication → KEV addition | 4 of 4 | 3.25 / 0 days | A complete cohort measure of public-record and catalog timing, not attacker dwell time. |
| CVE publication → initial patch | 2 of 4: Check Point only | 0 / 0 days | Two same-day publication/fix pairs. No full-cohort mean is claimed. |
| Initial patch → KEV addition | 2 of 4: Check Point only | 6.5 / 6.5 days | The subset values are 0 and 13; this result cannot represent all four entries. |
| Patch → true first exploitation | No complete exact-date set | Unavailable | Observed dates and unbounded earlier activity do not establish an exact first occurrence. |
| KEV addition → catalog due date | 4 of 4 | 3 / 3 days | A catalog deadline interval, not a safe deployment window. |
The exploitation findings answer a different question. The management case supplies a minimum 61-day pre-patch lead; the VPN case supplies an observation 3 days after the initial patch. Averaging these into a single response-time target would erase their different meanings.
CVE Timeline Data
All dates below are in 2026. “Unavailable” means the reviewed evidence does not establish the exact date or interval; it does not mean that no patch or exploitation exists.
| CVE ID | CVE Published | Patch Availability Evidence | Dated Exploitation Evidence | KEV Added | Days: Publication → Patch | Days: Patch → Observed Attack | Days: Publication → KEV |
|---|---|---|---|---|---|---|---|
| CVE-2026-93952 | September 22 | Fixed VCO versions are identified; exact first release dates are unavailable. | Active exploitation confirmed; no dated first attack established. | September 22 | Unavailable | Unavailable | 0 |
| CVE-2026-94127 | September 22 | Fixed engineering hotfixes available by September 22; exact earliest release date unconfirmed. | Exploitation confirmed; no dated first attack established. | September 22 | No exact value; by-date evidence is not an exact release date. | Unavailable | 0 |
| CVE-2026-93616 | September 22 | September 22: initial fix explicitly announced. | Targeted attacks observed July 23. | September 22 | 0 | −61 to the documented observation; true first-exploitation gap may be more negative. | 0 |
| CVE-2026-85102 | September 9 | September 9: initial fix explicitly documented. | Spark exploitation attempts observed from September 12. | September 22 | 0 | +3 to the observed exploitation attempts; not a proven first-ever attack interval. | 13 |
Affected scope and documented remedies
The following identifies remedies in the reviewed advisories, not a claim that every listed build was distributed on the initial P date. Match the product, configuration, release branch, and installed hotfix together.
| CVE / Product | Published Affected Scope | Documented Remedy | Important Qualification |
|---|---|---|---|
| CVE-2026-93952 VeloCloud Orchestrator | 5.2.x through 5.2.3.15; 6.1.x through 6.1.3.7; 6.4.x through 6.4.2.7; 7.0.x through 7.0.0.2. | 5.2.3.16 in the 5.2.3 train; 6.4.2.8 in the 6.4.2 train. | No 6.1 or 7.0 fix is named in the reviewed advisory. Hosted and Dedicated VCO are reported patched; Edge and Gateway are not directly affected products. |
| CVE-2026-94127 F5 BIG-IP APM | Affected 17.1, 17.5, and 21.1 branches with the OAuth Authorization Server configuration described above. | Hotfix-BIGIP-17.1.3.5.0.41.14-ENGHotfix-BIGIP-17.5.1.9.0.160.12-ENGHotfix-BIGIP-21.1.0.2.0.30.22-ENG | Verify the named engineering hotfix, not merely its base image. Versions beyond technical support were not evaluated. |
| CVE-2026-93616 Check Point management / logging | R82.20 without the fix; R82.10 through Take 44; R82 through Take 126; R81.20 through Take 166; R81.10 through Take 190. Older end-of-support releases are also listed. | R82.20 Security Hotfix; R82.10 Take 45; R82 Take 127; R81.20 Take 170; R81.10 Take 192. | Use the applicable branch remedy. LivePatch Take 28/29 does not fix this issue; the advisory states that a LivePatch is not available for it. |
| CVE-2026-85102 Check Point VPN gateways | Certificate-enabled VPN on affected Security Gateway and Spark releases, including R81.20, R82, R82.10, R81.10.x, R82.00.x, and listed end-of-support versions. R82.20 is listed as unaffected. | Jumbo fixes: R82.10 Take 44; R82 Take 126; R81.20 Take 166; R81.10 Take 190. Spark fixes: R82.00.10 Build 2325; R81.10.17 Build 4968. The advisory also documents LivePatch remediation. | A September 14 update requires Live Patch Take 26 for specified older-Jumbo installations that used the offline package. Do not assume every initial offline installation had equivalent coverage. |
A fix for one Check Point CVE is not proof that the other is resolved. The management and VPN advisories name different affected roles and different minimum Jumbo Takes. A branch version alone cannot establish both patch states.
Statistical Distribution and Outliers
Three of four publication-to-KEV observations are zero, and one is 13 days. The range is therefore 13 days. CVE-2026-85102 drives the mean upward; the median preserves the same-day pattern present in most of this small cohort.
The 61-day management finding is an exploitation-history distinction, not a 61-day publication-to-KEV outlier. Mixing it into that distribution would combine different event pairs. It also does not establish a continuous 61-day campaign, a compromise duration on every affected system, or an industry-wide zero-day average.
Because only two entries have exact initial patch dates, the patch-based subset is descriptive rather than representative. The unavailable dates are retained as missing evidence, not replaced with zero or removed without disclosure.
Vulnerability Class Breakdown
| CVE | Vulnerability Class | CWE | Published Severity | Publication → KEV |
|---|---|---|---|---|
| CVE-2026-93952 | Improper input validation | CWE-20 | Critical: CVSS v3.1 10.0; v4.0 9.5 | 0 days |
| CVE-2026-94127 | Heap-based buffer overflow; unauthenticated remote code execution | CWE-122 | Critical: CVSS v3.1 9.8; v4.0 9.3 | 0 days |
| CVE-2026-93616 | Path traversal / file upload enabling arbitrary script execution | CWE-22 | Critical: CVSS v3.1 9.8 | 0 days |
| CVE-2026-85102 | Improper certificate validation enabling unauthenticated remote code execution | CWE-295 | Critical: CVSS v3.1 9.8 | 13 days |
These are the CNA-provided CVSS assessments, with score versions preserved. There is one observation per CWE and no meaningful spread across severity bands. The dataset cannot establish that one vulnerability class consistently receives faster patches or is exploited sooner than another.
Notable Case Highlights
CVE-2026-93616: a pre-patch history hidden by same-day catalog timing
The vendor identifies this management issue as a zero-day and describes limited, targeted exploitation. The dated observation establishes the minimum pre-patch lead; it does not identify the first attack against any customer. An investigation beginning only at disclosure would omit the earlier documented activity.
CVE-2026-85102: post-patch observation is not a guaranteed grace period
The three-day initial-fix-to-observation interval is a recorded sequence, not an estimate of how long an organization could safely wait. The later offline-LivePatch coverage update also makes deployment validation important: “a patch was installed” is not equivalent to proving that the relevant configuration is covered.
CVE-2026-93952 and CVE-2026-94127: fixed builds do not date the first attack
Both have explicit exploitation confirmation and identified software remedies. Neither reviewed record establishes a precise first-attack day. The article therefore retains their urgency without inventing zero-day durations or assigning the advisory publication date to every patch release.
CVE-2026-94127 and CVE-2026-93952: additional zero-day exploitation reports
F5 states that CVE-2026-94127 has been exploited, while reporting on CVE-2026-93952 also describes exploitation as a zero-day; these cases show that the cohort includes multiple vulnerabilities with reported exploitation before or around disclosure, not only the Check Point management flaw.
Historical Trend Comparison
No independently verified prior-period comparison dataset is included in this analysis, so none is treated as a validated statistical baseline.
A defensible comparison would use the same date fields, missing-data rules, and treatment of shared release events. With four CVEs from three suppliers and incomplete exact patch dates, this post cannot establish that exploitation is accelerating or that patch gaps are widening or narrowing across the series.
MITRE ATT&CK Mapping
One limited mapping is supported by reported follow-up behavior. It is an analytical interpretation, not an ATT&CK sequence inferred from the vulnerability classes.
| Tactic | Technique | Evidence and Scope |
|---|---|---|
| Discovery | T1046 - Network Service Discovery | The VPN exploitation advisory describes follow-up internal port and service scanning. That behavior supports this mapping for the reported CVE-2026-85102 activity, not for all four CVEs. |
No cohort-wide persistence, defense-evasion, or command-and-control chain is assigned. Exploitation capability alone is not evidence that every possible post-exploitation technique occurred.
Risk Context for Organizations
The relevant risk is not captured by the median publication-to-KEV gap. Same-day catalog recognition does not imply same-day attacker discovery, and applying a fix cannot retrospectively rule out compromise before that fix became available.
| CVE | Catalog Due Date | Forensic Triage | Known Ransomware Campaign Use |
|---|---|---|---|
| CVE-2026-93952 | September 25, 2026 | Yes | Unknown |
| CVE-2026-94127 | September 25, 2026 | Yes | Unknown |
| CVE-2026-93616 | September 25, 2026 | Yes | Unknown |
| CVE-2026-85102 | September 25, 2026 | Yes | Unknown |
All four recorded due dates had passed at the September 28 review. “Unknown” is not evidence that ransomware use is absent. CISA’s September 22 alert places BOD 26-04 requirements within Federal Civilian Executive Branch agencies; the catalog deadline should not be presented as a universal legal deadline for every organization.
For other organizations, exposure, product role, evidence of compromise, and the availability of a validated remedy should drive the response. The analysis does not infer that every deployment of a listed product is reachable or exploitable.
Detection and Patch Prioritization Considerations
Validate applicability before treating a version match as a complete finding. Confirm the relevant product role and configuration as well as the installed build. In particular, do not merge Check Point management remediation with VPN remediation, or use F5’s base release number as proof that the named engineering hotfix is installed.
Preserve a separate compromise-assessment workstream. Review retained evidence for the documented pre-disclosure period, while recognizing that an observed date is not an absolute starting boundary. A clean result from an incomplete log-retention window cannot establish that earlier activity never occurred.
Keep temporary mitigation distinct from final remediation. The F5 KEV entry specifically describes a vendor-provided iRule for temporary protection during proactive forensic triage, followed by the final patch as soon as possible. That instruction is not a reason to leave temporary mitigation in place indefinitely.
Track closure at the asset level. Record the applied branch-specific remedy, configuration checks, triage findings, and unresolved exceptions. An advisory, a download, or a group-average gap is not evidence that an individual device has been remediated.
Key Takeaways
- CVE-2026-93616 has a minimum 61-day pre-patch exploitation lead, despite same-day CVE publication and KEV addition.
- The complete publication-to-KEV dataset has a 3.25-day mean and a median of 0 calendar days; those values do not measure the start or duration of attacks.
- The VPN case has documented exploitation attempts after the initial patch, but no guaranteed three-day grace period follows from that sequence.
- Exact four-CVE patch-to-first-exploitation statistics are unavailable; identified fixed builds do not justify inventing missing release or attack dates.
- All four KEV records call for forensic triage. Patch verification and compromise assessment answer different questions and should remain separate.
Conclusion
The September 22 cohort shows why publication, patch availability, attack observations, and KEV inclusion must remain distinct events. The shortest catalog interval in this dataset coexists with a substantial documented pre-patch exploitation history.
For ongoing patch management and compliance monitoring, retain the original date fields, show the limits of the evidence, and verify remediation on the deployed asset. A precisely bounded finding is more useful than an unsupported average, and a completed software update is not a substitute for assessing prior compromise.
Constantly Fix Risks with Saner Patch Management
Saner Patch Management is a continuous, automated, and integrated patch management solution that helps organizations identify, prioritize, and remediate vulnerabilities actively exploited in the wild. It supports Windows, Linux, macOS, and more than 550 third-party applications, enabling timely deployment of security updates across enterprise environments.
The platform also provides safe patch testing environments, automated deployment workflows, compliance reporting, and patch rollback capabilities to minimize operational risk while ensuring critical vulnerabilities are addressed without delay.
Experience the fastest and most accurate patching software here.




