Four-hour ranking: 1) Check Point, 2) F5 BIG-IP APM, 3) WSO2. Today’s Check Point evidence closes the strongest attack chain: Check Point and Qualys report active exploitation; CVE-2026-85102 permits unauthenticated remote code execution during VPN negotiation, while CVE-2026-93616 permits pre-authentication file upload and script execution on management and logging servers. WSO2 CVE-2026-5430 is reportedly exploited in the wild, but the available evidence does not establish its exploit primitive or post-exploitation indicators. That uncertainty puts it third—not on hold.
Check Point: hotfix-and-hunt is acceptable only if every gateway and management/logging server is inventoried, patched, and covered by complete VPN-negotiation, web-access, audit, process, file-integrity, and egress telemetry for its entire exposure period. Internet exposure plus any material logging gap means isolate and preserve disks, memory, configuration, and logs. Uploaded scripts, unexpected child processes, unauthorized policy or administrator changes, or unexplained egress trigger rotation of all credentials and private keys accessible from the affected system. Confirmed execution, persistence, management-plane modification, or unverifiable filesystem integrity means rebuild from known-good media.
F5: yesterday’s operational conclusion stands, but the technical characterization needs caution. The available reporting says CVE-2026-94127 is actively exploited; a Picus write-up describes it as a heap-overflow attack, but the exact exploitation primitive and privilege context remain pending stronger primary-source confirmation. Patch-and-hunt requires complete APM request, daemon, audit, crash/core, configuration-change, authentication, and egress records. Exposure combined with missing logs, unexplained crashes or restarts, configuration drift, or suspicious process activity means isolate and preserve evidence. Rotate APM-accessible credentials, sessions, and keys after suspected execution or unauthorized configuration access; rebuild when persistence, privileged execution, management-plane tampering, or unresolved integrity loss is present.
WSO2: patch immediately, but do not pretend sparse exploit detail supports precise IOC hunting. Hotfix-and-hunt requires complete ingress/API, application-audit, process, filesystem, workload, and egress telemetry across the exposure window. An exposed control plane with missing telemetry moves to isolation and evidence preservation. Unexpected child processes, file or image drift, new users or tokens, and unexplained egress trigger rotation of OAuth clients, signing material, API tokens, and service credentials reachable from WSO2. Confirmed execution, persistence, or unverifiable image integrity means redeploy from a known-good image.