SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Patch Analysis & Exploitation Timeline: A Check Point Flaw Exploited 61 Days Before Its Fix Leads CISA's September 22, 2026 KEV Additions

Patch Analysis & Exploitation Timeline: A Check Point Flaw Exploited 61 Days Before Its Fix Leads CISA's September 22, 2026 KEV Additions

Four CVEs entered CISA’s KEV catalog on September 22, 2026, but their exploitation histories differ. A Check Point management zero-day had documented attacks at least 61 days before its fix, while VPN exploitation attempts were observed three days after an initial patch. This analysis separates attack observations, patch evidence, and catalog timing.

Oct 1, 2026By Emandi Srinivas

Dataset Summary

FieldValueInterpretation
Reporting PeriodSeptember 22, 2026 KEV additionsThe supporting chronology spans July 23–September 22, 2026. Sources were reviewed on September 28; the recorded remediation deadline was September 25.
Data SourcesCISA KEV; official CVE records; product security advisoriesPublic primary sources provide the additional dates, affected configurations, and remediation details.
Total CVEs Analyzed4CVE-2026-93952, CVE-2026-94127, CVE-2026-93616, and CVE-2026-85102. No additional CVEs enter the calculations.
Average Disclosure-to-Patch GapFull-cohort value unavailableUsing CVE publication as the disclosure field, the two Check Point cases with explicitly dated initial fixes each yield 0 calendar days. Their mean and median are 0; this is a two-record subset, not a four-CVE result.
Average Patch-to-Exploitation GapUnavailableThe true first-exploitation date is not established for every entry. A dated attack observation, a publication date, and KEV inclusion are not interchangeable.
Average / Median CVE-Publication-to-KEV Gap3.25 days / 0 daysAll four records have confirmed publication and catalog dates. Three entered KEV on their CVE publication date; the VPN certificate-validation CVE entered 13 days later.
Shortest / Longest Publication-to-KEV Gap0 days / 13 daysCVE-2026-93952, CVE-2026-94127, and CVE-2026-93616 tie at 0. CVE-2026-85102 accounts for the 13-day maximum.
Documented Pre-Patch Exploitation LeadCVE-2026-93616: at least 61 daysA July 23 attack observation predates the September 22 fix. This is a minimum lead relative to the documented fix, not proof of continuous attacks throughout the interval.
Post-Patch Exploitation-Attempt ObservationCVE-2026-85102: 3 days after the initial fixA wave of VPN exploitation attempts was observed from September 12, following the September 9 fix. This does not prove there were no earlier attempts or compromises.
KEV-to-Due-Date Interval3 calendar days for all fourSeptember 22 to September 25. Every entry records forensic triage as “Yes” and known ransomware campaign use as “Unknown.”

Sourcing and Methodology Note

The four-CVE selection is corroborated by CISA’s CISA Adds Four Known Exploited Vulnerabilities to Catalog alert of September 22, 2026. The KEV catalog, version 2026.09.27, supplies catalog dates and response fields; the four official CVE Program records supply publication dates, weakness classifications, and version-labeled severity scores.

Technical and patch references are Security Advisory 0183; F5 articles K000162605 and K000163302; and Check Point articles sk1000117 and sk1000171. The September 22 Check Point exploitation advisory supplies the dated attack observations and initial fix dates. Official security guidance AL26-022 corroborates F5 hotfix availability by September 22. MITRE ATT&CK T1046 supports the limited behavioral mapping below.

Sources were reviewed on September 28, 2026. Calendar-day calculations and operational interpretation are SecPod’s analytical layer. “Known exploitation” means an explicit exploitation report or KEV inclusion; neither alone establishes mass exploitation. Missing first-attack or exact release dates remain unavailable, and partial-sample results are labeled.

Introduction

One vulnerability in the September 22 KEV additions had documented attacks at least 61 days before its fix. For CVE-2026-93616, the management-server attack observation and the patch date establish a substantial pre-patch lead. Yet its CVE publication and KEV addition occurred on the same calendar day.

This contrast is the central finding: same-day CVE publication and KEV addition can coexist with a much older exploitation history. The four-entry dataset also includes a VPN case with dated post-patch exploitation attempts, alongside VeloCloud and F5 cases whose exact first-attack dates remain unconfirmed.

Background and Context

The dataset spans orchestration, access-policy processing, management servers, and VPN gateways. These are different exposure paths, not four interchangeable instances of the same vulnerability.

VeloCloud exposure depends on certificate-based Edge-to-Orchestrator authentication, access to the public portion of an Edge authentication certificate, and network reachability to the VCO web interface. Tenant or operator credentials are not required.

For F5, the affected configuration is BIG-IP APM acting as an OAuth Authorization Server, with the relevant access policy and OAuth profile on a virtual server. OAuth Client or Resource Server use alone, without an authorization-server profile, is excluded by the CVE description. The exposure is in the data plane, not the control plane.

The Check Point entries must also remain separate. CVE-2026-93616 concerns management and logging products; CVE-2026-85102 concerns VPN certificate validation on Security Gateway and Spark Firewall. The VPN advisory excludes gateways participating only in pre-shared-key encryption communities; mixed configurations and certificate-enabled communities require separate assessment.

Gap Calculation Methodology

D is the UTC calendar date in the CVE record’s datePublished field. P is an explicitly dated initial fix release. B is a dated attack observation. E is the true first-exploitation date, which may precede B. K and R are KEV’s addition and due dates.

CVE-Publication-to-Patch Gap = P − D

CVE-Publication-to-KEV Gap = K − D

Patch-to-KEV Gap = K − P

Patch-to-Observed-Attack Interval = B − P

Minimum Pre-Patch Lead = P − B, when B precedes P

Actual Patch-to-First-Exploitation Gap = E − P

Calculations subtract calendar dates without inclusive counting. A same-day result does not establish the order of events within that day. CVE publication is used consistently for D; a knowledge-base article’s creation or modification timestamp is not silently substituted for public disclosure.

The Check Point initial fix dates are explicitly documented. F5 hotfixes are corroborated as available by September 22, but that does not independently establish their earliest release date. VeloCloud’s reviewed advisory identifies fixed versions without separately dating each release. Those two cases are excluded from exact P-based averages, not from the four-CVE dataset.

P describes the initial documented remedy, not the release date of every later hotfix, build, or coverage enhancement. B is an observation, not proof of E. Accordingly, the article does not convert bounded or missing dates into an exact four-CVE exploitation average.

Patch Timeline & Exploitation Gap Analysis

The complete publication-to-KEV distribution is [0, 0, 0, 13] calendar days. Its mean is 3.25 days, while its median is 0 days. The mean exceeds the median because one record has a materially longer interval; it does not imply that any individual CVE took 3.25 days to enter the catalog.

MetricUsable RecordsMean / MedianInterpretation
CVE publication → KEV addition4 of 43.25 / 0 daysA complete cohort measure of public-record and catalog timing, not attacker dwell time.
CVE publication → initial patch2 of 4: Check Point only0 / 0 daysTwo same-day publication/fix pairs. No full-cohort mean is claimed.
Initial patch → KEV addition2 of 4: Check Point only6.5 / 6.5 daysThe subset values are 0 and 13; this result cannot represent all four entries.
Patch → true first exploitationNo complete exact-date setUnavailableObserved dates and unbounded earlier activity do not establish an exact first occurrence.
KEV addition → catalog due date4 of 43 / 3 daysA catalog deadline interval, not a safe deployment window.

The exploitation findings answer a different question. The management case supplies a minimum 61-day pre-patch lead; the VPN case supplies an observation 3 days after the initial patch. Averaging these into a single response-time target would erase their different meanings.

CVE Timeline Data

All dates below are in 2026. “Unavailable” means the reviewed evidence does not establish the exact date or interval; it does not mean that no patch or exploitation exists.

CVE IDCVE PublishedPatch Availability EvidenceDated Exploitation EvidenceKEV AddedDays: Publication → PatchDays: Patch → Observed AttackDays: Publication → KEV
CVE-2026-93952September 22Fixed VCO versions are identified; exact first release dates are unavailable.Active exploitation confirmed; no dated first attack established.September 22UnavailableUnavailable0
CVE-2026-94127September 22Fixed engineering hotfixes available by September 22; exact earliest release date unconfirmed.Exploitation confirmed; no dated first attack established.September 22No exact value; by-date evidence is not an exact release date.Unavailable0
CVE-2026-93616September 22September 22: initial fix explicitly announced.Targeted attacks observed July 23.September 220−61 to the documented observation; true first-exploitation gap may be more negative.0
CVE-2026-85102September 9September 9: initial fix explicitly documented.Spark exploitation attempts observed from September 12.September 220+3 to the observed exploitation attempts; not a proven first-ever attack interval.13

Affected scope and documented remedies

The following identifies remedies in the reviewed advisories, not a claim that every listed build was distributed on the initial P date. Match the product, configuration, release branch, and installed hotfix together.

CVE / ProductPublished Affected ScopeDocumented RemedyImportant Qualification
CVE-2026-93952
VeloCloud Orchestrator
5.2.x through 5.2.3.15; 6.1.x through 6.1.3.7; 6.4.x through 6.4.2.7; 7.0.x through 7.0.0.2.5.2.3.16 in the 5.2.3 train; 6.4.2.8 in the 6.4.2 train.No 6.1 or 7.0 fix is named in the reviewed advisory. Hosted and Dedicated VCO are reported patched; Edge and Gateway are not directly affected products.
CVE-2026-94127
F5 BIG-IP APM
Affected 17.1, 17.5, and 21.1 branches with the OAuth Authorization Server configuration described above.Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
Verify the named engineering hotfix, not merely its base image. Versions beyond technical support were not evaluated.
CVE-2026-93616
Check Point management / logging
R82.20 without the fix; R82.10 through Take 44; R82 through Take 126; R81.20 through Take 166; R81.10 through Take 190. Older end-of-support releases are also listed.R82.20 Security Hotfix; R82.10 Take 45; R82 Take 127; R81.20 Take 170; R81.10 Take 192.Use the applicable branch remedy. LivePatch Take 28/29 does not fix this issue; the advisory states that a LivePatch is not available for it.
CVE-2026-85102
Check Point VPN gateways
Certificate-enabled VPN on affected Security Gateway and Spark releases, including R81.20, R82, R82.10, R81.10.x, R82.00.x, and listed end-of-support versions. R82.20 is listed as unaffected.Jumbo fixes: R82.10 Take 44; R82 Take 126; R81.20 Take 166; R81.10 Take 190. Spark fixes: R82.00.10 Build 2325; R81.10.17 Build 4968. The advisory also documents LivePatch remediation.A September 14 update requires Live Patch Take 26 for specified older-Jumbo installations that used the offline package. Do not assume every initial offline installation had equivalent coverage.

A fix for one Check Point CVE is not proof that the other is resolved. The management and VPN advisories name different affected roles and different minimum Jumbo Takes. A branch version alone cannot establish both patch states.

Statistical Distribution and Outliers

Three of four publication-to-KEV observations are zero, and one is 13 days. The range is therefore 13 days. CVE-2026-85102 drives the mean upward; the median preserves the same-day pattern present in most of this small cohort.

The 61-day management finding is an exploitation-history distinction, not a 61-day publication-to-KEV outlier. Mixing it into that distribution would combine different event pairs. It also does not establish a continuous 61-day campaign, a compromise duration on every affected system, or an industry-wide zero-day average.

Because only two entries have exact initial patch dates, the patch-based subset is descriptive rather than representative. The unavailable dates are retained as missing evidence, not replaced with zero or removed without disclosure.

Vulnerability Class Breakdown

CVEVulnerability ClassCWEPublished SeverityPublication → KEV
CVE-2026-93952Improper input validationCWE-20Critical: CVSS v3.1 10.0; v4.0 9.50 days
CVE-2026-94127Heap-based buffer overflow; unauthenticated remote code executionCWE-122Critical: CVSS v3.1 9.8; v4.0 9.30 days
CVE-2026-93616Path traversal / file upload enabling arbitrary script executionCWE-22Critical: CVSS v3.1 9.80 days
CVE-2026-85102Improper certificate validation enabling unauthenticated remote code executionCWE-295Critical: CVSS v3.1 9.813 days

These are the CNA-provided CVSS assessments, with score versions preserved. There is one observation per CWE and no meaningful spread across severity bands. The dataset cannot establish that one vulnerability class consistently receives faster patches or is exploited sooner than another.

Notable Case Highlights

CVE-2026-93616: a pre-patch history hidden by same-day catalog timing

The vendor identifies this management issue as a zero-day and describes limited, targeted exploitation. The dated observation establishes the minimum pre-patch lead; it does not identify the first attack against any customer. An investigation beginning only at disclosure would omit the earlier documented activity.

CVE-2026-85102: post-patch observation is not a guaranteed grace period

The three-day initial-fix-to-observation interval is a recorded sequence, not an estimate of how long an organization could safely wait. The later offline-LivePatch coverage update also makes deployment validation important: “a patch was installed” is not equivalent to proving that the relevant configuration is covered.

CVE-2026-93952 and CVE-2026-94127: fixed builds do not date the first attack

Both have explicit exploitation confirmation and identified software remedies. Neither reviewed record establishes a precise first-attack day. The article therefore retains their urgency without inventing zero-day durations or assigning the advisory publication date to every patch release.

CVE-2026-94127 and CVE-2026-93952: additional zero-day exploitation reports

F5 states that CVE-2026-94127 has been exploited, while reporting on CVE-2026-93952 also describes exploitation as a zero-day; these cases show that the cohort includes multiple vulnerabilities with reported exploitation before or around disclosure, not only the Check Point management flaw.

Historical Trend Comparison

No independently verified prior-period comparison dataset is included in this analysis, so none is treated as a validated statistical baseline.

A defensible comparison would use the same date fields, missing-data rules, and treatment of shared release events. With four CVEs from three suppliers and incomplete exact patch dates, this post cannot establish that exploitation is accelerating or that patch gaps are widening or narrowing across the series.

MITRE ATT&CK Mapping

One limited mapping is supported by reported follow-up behavior. It is an analytical interpretation, not an ATT&CK sequence inferred from the vulnerability classes.

TacticTechniqueEvidence and Scope
DiscoveryT1046 - Network Service DiscoveryThe VPN exploitation advisory describes follow-up internal port and service scanning. That behavior supports this mapping for the reported CVE-2026-85102 activity, not for all four CVEs.

No cohort-wide persistence, defense-evasion, or command-and-control chain is assigned. Exploitation capability alone is not evidence that every possible post-exploitation technique occurred.

Risk Context for Organizations

The relevant risk is not captured by the median publication-to-KEV gap. Same-day catalog recognition does not imply same-day attacker discovery, and applying a fix cannot retrospectively rule out compromise before that fix became available.

CVECatalog Due DateForensic TriageKnown Ransomware Campaign Use
CVE-2026-93952September 25, 2026YesUnknown
CVE-2026-94127September 25, 2026YesUnknown
CVE-2026-93616September 25, 2026YesUnknown
CVE-2026-85102September 25, 2026YesUnknown

All four recorded due dates had passed at the September 28 review. “Unknown” is not evidence that ransomware use is absent. CISA’s September 22 alert places BOD 26-04 requirements within Federal Civilian Executive Branch agencies; the catalog deadline should not be presented as a universal legal deadline for every organization.

For other organizations, exposure, product role, evidence of compromise, and the availability of a validated remedy should drive the response. The analysis does not infer that every deployment of a listed product is reachable or exploitable.

Detection and Patch Prioritization Considerations

Validate applicability before treating a version match as a complete finding. Confirm the relevant product role and configuration as well as the installed build. In particular, do not merge Check Point management remediation with VPN remediation, or use F5’s base release number as proof that the named engineering hotfix is installed.

Preserve a separate compromise-assessment workstream. Review retained evidence for the documented pre-disclosure period, while recognizing that an observed date is not an absolute starting boundary. A clean result from an incomplete log-retention window cannot establish that earlier activity never occurred.

Keep temporary mitigation distinct from final remediation. The F5 KEV entry specifically describes a vendor-provided iRule for temporary protection during proactive forensic triage, followed by the final patch as soon as possible. That instruction is not a reason to leave temporary mitigation in place indefinitely.

Track closure at the asset level. Record the applied branch-specific remedy, configuration checks, triage findings, and unresolved exceptions. An advisory, a download, or a group-average gap is not evidence that an individual device has been remediated.

Key Takeaways

  • CVE-2026-93616 has a minimum 61-day pre-patch exploitation lead, despite same-day CVE publication and KEV addition.
  • The complete publication-to-KEV dataset has a 3.25-day mean and a median of 0 calendar days; those values do not measure the start or duration of attacks.
  • The VPN case has documented exploitation attempts after the initial patch, but no guaranteed three-day grace period follows from that sequence.
  • Exact four-CVE patch-to-first-exploitation statistics are unavailable; identified fixed builds do not justify inventing missing release or attack dates.
  • All four KEV records call for forensic triage. Patch verification and compromise assessment answer different questions and should remain separate.

Conclusion

The September 22 cohort shows why publication, patch availability, attack observations, and KEV inclusion must remain distinct events. The shortest catalog interval in this dataset coexists with a substantial documented pre-patch exploitation history.

For ongoing patch management and compliance monitoring, retain the original date fields, show the limits of the evidence, and verify remediation on the deployed asset. A precisely bounded finding is more useful than an unsupported average, and a completed software update is not a substitute for assessing prior compromise.

Constantly Fix Risks with Saner Patch Management

Saner Patch Management is a continuous, automated, and integrated patch management solution that helps organizations identify, prioritize, and remediate vulnerabilities actively exploited in the wild. It supports Windows, Linux, macOS, and more than 550 third-party applications, enabling timely deployment of security updates across enterprise environments.

The platform also provides safe patch testing environments, automated deployment workflows, compliance reporting, and patch rollback capabilities to minimize operational risk while ensuring critical vulnerabilities are addressed without delay.

Experience the fastest and most accurate patching software here.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026