Two unauthenticated zero-days, one bad week
In the same week, CISA confirmed active exploitation of critical zero-days in two unrelated vendors' edge infrastructure products. F5's BIG-IP Access Policy Manager, the component that handles authentication and access control for applications sitting behind F5 load balancers, has a heap-based buffer overflow tracked as CVE-2026-94127 that researchers at watchtowr described as an unauthenticated heap overflow leading directly to remote code execution. It affects instances configured as an OAuth Authorization Server, meaning the exact systems enterprises rely on to broker trust for other applications are the ones exposed.
Arista's VeloCloud Orchestrator, the central management console for VeloCloud SD-WAN deployments, carries CVE-2026-93952, an improper input validation flaw that Arista itself called known to be actively exploited. The company's advisory was blunt: VCO tenant or operator credentials are not required to exploit it. An attacker needs only network access to the web interface and knowledge of a public VeloCloud Edge authentication certificate, something far easier to obtain than a stolen password. Both vendors confirmed CISA's assessment and both flaws landed in the KEV catalog with the same September 25 deadline for federal remediation.
Why OAuth servers and SD-WAN orchestrators are both crown jewels
F5 BIG-IP APM configured as an OAuth Authorization Server is not a peripheral system. It is the thing other applications trust to say who a user is, which makes a remote code execution bug there equivalent to compromising an identity provider. An attacker who pops the OAuth server can mint tokens, impersonate users, and pivot into every downstream application that trusts it, all without ever touching a password. That is a materially worse outcome than a typical RCE on an isolated server, because the blast radius is defined by how many applications trust that authorization server rather than by what's running on the box itself.
VeloCloud Orchestrator plays an equivalent role for SD-WAN: it is the single console that configures every edge device across a VeloCloud deployment. CVSS 10.0, the maximum possible score, reflects that an attacker who reaches privileged VCO functionality can push configuration to every managed edge simultaneously, turning a single unauthenticated bug into a fleet-wide compromise. Security architecture reviews tend to focus hardening effort on what a system protects directly; these two incidents are a reminder to weight hardening by what a system is trusted by, which is a different and often larger number.
Patch status and what to do if you cannot patch today
F5 published engineering hotfixes for three branches: 21.1.0.2.0.30.22, 17.5.1.9.0.160.12, and 17.1.3.5.0.41.14, alongside a temporary iRule mitigation available through F5 support for environments that need a bridge before a full hotfix rollout. Affected versions span 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3, which covers a wide installed base. Arista has shipped fixed VCO releases for its hosted 5.2.3.16 and 6.4.2.8 branches already, with patches for the 6.1.3.7 and 7.0.0.2 branches still rolling out at disclosure time, meaning on-prem VCO operators on those branches have a real gap to manage in the interim.
Where patching cannot happen immediately, both vendors point to the same interim control: restrict network reachability to the management interface. For F5, that means limiting who can reach the APM's OAuth endpoints at all, not just applying access control within the application. For Arista, that means restricting which networks can reach the VCO web interface, since the exploit path requires only network access plus a certificate value, not a valid login. Neither mitigation is a substitute for patching, but both buy time for change-management processes that cannot move at zero-day speed.
The attribution gap is itself a signal
Neither F5 nor Arista, nor CISA's KEV entries, named an attacker for either vulnerability, and that silence is worth noting rather than ignoring. Vendors increasingly withhold attribution details when an investigation is active or when the exploitation appears opportunistic and widespread rather than tied to one identifiable campaign, which tends to mean a broader population of victims across sectors rather than a narrow, targeted operation against a handful of named organizations. For risk teams, an absence of attribution is not reassurance; if anything it argues for faster, broader remediation, because the lack of a named target profile means every internet-facing instance is a candidate.
It is also worth noting both vendors found out about their own zero-days from external researchers or third-party reporting rather than internal detection, a pattern that has repeated across most of 2026's highest-severity disclosures. That argues for CISOs to weight a vendor's bug bounty program and external disclosure track record as part of procurement risk, alongside the more conventional criteria of SOC 2 reports and penetration test cadence. A vendor that works well with external researchers tends to close these gaps faster once found.
What CISOs should take into the next board update
Both vulnerabilities belong in the same board-level sentence: our edge infrastructure, not just our applications, is a direct attack surface, and it is being treated by attackers as such. Enterprise security budgets have historically weighted application security and endpoint detection more heavily than the load balancers, SD-WAN controllers, and VPN concentrators that sit at network boundaries, a gap this week's disclosures make hard to defend. If your BIG-IP or VeloCloud footprint has not had an independent configuration review in the past year, this is the natural trigger to schedule one.
For PE-backed portfolio companies in particular, where infrastructure inventories are often inherited through acquisition and poorly centrally tracked, the immediate action is a rapid inventory sweep: which portfolio companies run BIG-IP APM as an OAuth server, which run VeloCloud Orchestrator, and what is each one's actual patch status today, not what procurement assumed six months ago. That inventory gap, more than any single CVE, is the recurring finding that turns a patchable zero-day into an actual breach.


_Pattara_Alamy.jpg)
