Safeguard
Vulnerability Analysis

F5, Check Point, Versa, and Arista: Four Vendors, One Edge Infrastructure Problem

A BIG-IP APM buffer overflow, a ransomware-linked Check Point VPN authentication bypass, a Versa Concerto proxy misconfiguration, and an Arista EOS tunnel decapsulation flaw all failed at the same job: enforcing a boundary.

Safeguard Research Team
5 min read

Four vendors, four unrelated products, one shared category: network edge and VPN infrastructure — the boxes and orchestration platforms that sit between an organization's internal network and the outside world. Arista's switching OS, Check Point's VPN gateway, F5's application delivery controller, and Versa's SD-WAN orchestrator each produced a confirmed-exploited vulnerability, and together they make the case that "edge infrastructure" is a coherent risk category regardless of which specific vendor built the box.

CVECVSSVendor / ProductAdded to KEVRansomware use
CVE-2025-535219.8F5 BIG-IP APM (stack buffer overflow)27 Mar 2026Unknown
CVE-2026-507519.3Check Point Security Gateway (IKEv1 auth bypass)8 Jun 2026Known
CVE-2025-340267.5Versa Concerto (Traefik/Actuator auth bypass)22 Jan 2026Unknown
CVE-2026-74735.8Arista EOS (tunnel decapsulation logic error)9 Jun 2026Unknown

Why the failure mode is almost always the same: a boundary that stopped checking what crossed it

Every device in this cluster exists to enforce a boundary — VPN authentication, tunnel decapsulation, administrative access control, application traffic inspection — and every CVE here is a failure of exactly that enforcement, not some unrelated feature bug. CVE-2025-53521 is a stack-based buffer overflow in F5 BIG-IP's Access Policy Manager: when an access policy is configured on a virtual server, "specific malicious traffic can lead to Remote Code Execution," per NVD. The component whose entire job is deciding who gets access is the one with the RCE.

CVE-2026-50751 in Check Point is even more direct about what broke: a "logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password." This CVE carries CISA's confirmed ransomware flag — an attacker doesn't need any credential at all to get a working VPN session, which is functionally identical to stolen valid credentials from a detection standpoint, since there's no failed-login trail to alert on.

CVE-2025-34026 in Versa Concerto is a supporting-infrastructure failure rather than a core VPN or firewall bug: the SD-WAN orchestration platform's Traefik reverse-proxy configuration doesn't properly gate access to administrative endpoints, and NVD notes "the internal Actuator endpoint can be leveraged for access to heap dumps and trace logs" — a diagnostic feature never meant to be internet-reachable, exposed by a misconfigured proxy layer sitting in front of it.

CVE-2026-7473's Arista bug is structurally distinct but belongs in the same boundary-enforcement category: EOS switches with VXLAN, decap-groups, or GRE tunnel decapsulation configured will incorrectly decapsulate and forward "other unexpected tunneled packet with a destination IP matching its configured decapsulation IP," because, per NVD, "the switch does not verify the tunnel protocol type." The switch checks the destination IP but not what kind of tunnel it's supposed to be — an incomplete comparison that lets unrelated tunnel traffic slip through a boundary meant to filter by protocol as well as address.

Why grouping these four together matters despite different vendors

None of these four products would normally be reviewed in the same remediation cycle — they come from unrelated vendors with unrelated support contracts and unrelated patch cadences. But an organization's actual network perimeter is usually built from exactly this kind of multi-vendor mix: a firewall from one company, VPN gateway from another, SD-WAN fabric from a third, switching fabric from a fourth. A vulnerability-management program organized strictly by vendor will handle each of these four in isolation and miss that they collectively define this quarter's edge-infrastructure risk.

What to check this week

Patch F5 BIG-IP APM and Check Point Security Gateway with priority, given their 9.8 and 9.3 severity scores and Check Point's confirmed ransomware association — both represent the most severe and most actively weaponized findings in this group.

Deprecate IKEv1 VPN configurations on Check Point gateways where feasible, since CVE-2026-50751 specifically targets the "deprecated IKEv1 key exchange" — moving to a modern key-exchange protocol removes the vulnerable code path entirely rather than just patching it.

Audit Versa Concerto's Traefik reverse-proxy rules for exposed administrative and Actuator endpoints, confirming diagnostic interfaces aren't reachable beyond the internal network segment that legitimately needs them.

Review EOS tunnel decapsulation configurations for exposure, particularly on switches where VXLAN, decap-groups, or GRE interfaces are active, since CVE-2026-7473 requires that configuration to be present to be exploitable.

A closing note on multi-vendor perimeter risk

The fact that four unrelated vendors each produced a confirmed-exploited boundary-enforcement bug in roughly the same window isn't evidence of unusually poor engineering at any one of them — it reflects how much of the modern network perimeter is now software, and how consistently "software that enforces a boundary" turns out to be where boundary-enforcement bugs live.

A final consideration on diagnostic and management interfaces

Versa's Actuator exposure and F5's access-policy RCE both point to the same underlying lesson: administrative and diagnostic interfaces need their own explicit exposure review, separate from whatever network segmentation already exists for the product's primary function, because a proxy misconfiguration or a policy-processing bug can silently reopen a path that was never intended to be internet-facing.

How Safeguard helps

Safeguard's continuous inventory treats network edge and VPN infrastructure as a single risk category across vendors, so that a multi-vendor perimeter — firewall from one supplier, VPN gateway from another, SD-WAN orchestration from a third — gets evaluated as the connected attack surface it actually is, rather than as four disconnected vendor relationships.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.