Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Edge Appliances Under Fire: F5 BIG-IP APM, Ivanti Sentry, Progress LoadMaster, VeloCloud Exploited (2026)

Critical CVE-2026-94127, CVE-2026-10520, CVE-2026-8037, CVE-2026-93952, CVE-2026-16812, CVE-2026-7473 — A roundup of exploited 2026 bugs in network edge appliances: F5 BIG-IP APM OAuth RCE (CVE-2026-94127), Ivanti Sentry root RCE (CVE-2026-10520), Progress LoadMaster command injection (CVE-2026-8037), Arista VeloCloud Orchestrator (CVSS 10), and Arista EOS tunnel bypass.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Load balancers, gateways and SD-WAN orchestrators sit on the internet edge and keep getting hit. Five exploited 2026 bugs give unauthenticated remote code execution: F5 BIG-IP APM as OAuth authorization server, Ivanti Sentry (root), Progress LoadMaster / MOVEit WAF, and two in Arista VeloCloud Orchestrator on-prem. A sixth lets traffic slip through Arista EOS tunnels. Patch versions are below.

CVE-2026-94127F5 BIG-IP APM configured as an OAuth Authorization Server → unauthenticated RCE. CVSS 9.8. KEV 2026-09-22
CVE-2026-10520Ivanti Sentry OS command injection → unauthenticated root RCE. CVSS 10. Fixed R10.5.2 / R10.6.2 / R10.7.1. KEV 2026-06-11
CVE-2026-8037Progress LoadMaster, ECS/ObjectScale Connection Manager, MOVEit WAF: API command injection. CVSS 9.6. KEV 2026-08-07
CVE-2026-16812 / 93952Arista VeloCloud Orchestrator on-prem: internal functionality reachable remotely. CVSS 10. KEV 2026-07-27 / 2026-09-22
CVE-2026-7473Arista EOS decapsulates unexpected tunnel types → forwarding bypass. CVSS 5.8. KEV 2026-06-09

F5 BIG-IP APM: CVE-2026-94127

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server and APM is acting as an OAuth Authorization Server, specific malicious traffic leads to unauthenticated remote code execution. Deployments that use APM only as an OAuth client or resource server are not affected. F5 published engineering hotfixes for 21.1.0, 17.5.x and 17.1.x and an iRule mitigation in K000162605; CISA asks agencies to apply the iRule, do forensic triage, then install the final patch.

tmsh show sys version
tmsh list apm oauth oauth-profile    # any authorization-server profiles?

Ivanti Sentry: CVE-2026-10520

Ivanti Sentry (the gateway in front of Exchange/ActiveSync and other back-ends for Ivanti EPMM/MobileIron) has an OS command injection that gives a remote unauthenticated attacker root. Upgrade to R10.5.2, R10.6.2 or R10.7.1. Keep the Sentry System Manager portal (MICS, port 8443) off the internet.

Progress LoadMaster / MOVEit WAF: CVE-2026-8037

Unsanitised input in several API command endpoints lets an unauthenticated attacker run commands on the appliance. Affected: LoadMaster V7.2.45.12–V7.2.54.17 and V7.2.60.0–V7.2.63.1, plus ECS Connection Manager, ObjectScale Connection Manager and MOVEit WAF on the 7.2.60 line. Upgrade to the fixed builds in Progress’s June 2026 bulletin (V7.2.54.18 / V7.2.63.2 or later), and disable the REST API if you don’t use it (Certificates & Security → Remote Access).

Arista VeloCloud Orchestrator: CVE-2026-16812 and CVE-2026-93952

Two separate bugs in the on-premises VeloCloud Orchestrator (VCO), the SD-WAN management plane formerly sold by VMware, let a remote attacker reach internal-only functionality and take over the orchestrator, and through it every edge it manages. Hosted and dedicated VCO instances were patched by Arista.

VCO lineFixed for 16812Fixed for 93952 (newest)
5.25.2.3.145.2.3.15
6.16.1.3.46.1.3.7
6.46.4.2.46.4.2.7
7.07.0.0.17.0.0.2

Arista EOS: CVE-2026-7473

Switches with tunnel decapsulation configured (VXLAN, decap-groups, GRE) decapsulate and forward other tunnel types sent to the same IP, because the tunnel protocol isn’t verified. Attackers can use that to inject traffic past ACLs. Affects EOS 4.31 through 4.36; see Arista advisory 0137 for fixed releases and the ACL mitigation.

What to do for all of these

  • Patch first; these are all being exploited.
  • Keep management interfaces and APIs on a dedicated management network.
  • After patching an internet-facing appliance that was vulnerable, assume possible compromise: review admin accounts and config changes, rotate credentials and certificates it holds, and check vendor-published IOCs.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories