Handler on Duty: Brad Duncan
Threat Level: green
Podcast Detail
SANS Stormcast Wednesday, September 23rd, 2026: GET with Body; Checkpoint, VeloCloud, BigIP and Microsoft Defender 0-days
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10106.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
The Truth about GET and HTTP Standards
https://isc.sans.edu/diary/The%20Truth%20about%20GET%20and%20HTTP%20Standards/33358
CVE-2026-93616: 0-Day Remote Code Execution Vulnerability patch in Checkpoint Management Server
https://support.checkpoint.com/results/sk/sk1000171/
VeloCloud Orchestrator (VCO) Patch for Exploited Vulnerability CVE-2026-93952
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
F5 BigIP APM Exploited Vulnerability Patched CVE-2026-94127
https://my.f5.com/manage/s/article/K000162605
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Wednesday, September 22, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Las Vegas, Nevada. And this episode is brought to you by the SANS.edu Graduate Certificate Program in Cyber Defense Operations. I brought a diary today a little bit as a follow up to what Xavier wrote on Friday about the query method in HTTP that was recently introduced just to look into hey what actually happens when you send a body with the GET request. Well it turns out that the RFC weren't always very specific about what to do in this case and as a result it really varies a little bit by web server. Apache actually is perfectly fine with a body as part of a GET request. Most other web servers will just ignore it even if you send a content length header. Now one that actually sends an error back is lighthttpd. That's a web server you often see sort of in IoT devices. But as of a rule of thumb the body is just ignored and no errors being sent back. It's basically just treated like a GET request without the body. Well today we got a couple of series to talk about. First of his vulnerability that's already being exploited against the checkpoint management server. This is an arbitrary code execution vulnerability. It's one of those file upload issues where an attacker is able to exploit a directory traversal vulnerability to upload a file that then can be used to execute arbitrary code. A patch has been released today in the form of a hotfix. So please apply it. Apply it quickly. Yes the management server should not be exposed to the internet but this would still be an extremely juicy opportunity for some lateral movement for an attacker. So definitely this will will soon be attacked more widely. And Arista released an advisory patching an actively exploited vulnerability for VeloCloud orchestrator. This affects the on premise version and has a CVSS version 3.1 base score of 10 and version 4.0 base score of 9.5. The advisor is a little bit vague here what exactly is happening. But given the CVSS score and the and stating that the remote attacker that has access to this vulnerability may exploit it to compromise the confidentiality, integrity and availability of the orchestrator. So I would probably call this a code execution vulnerability. Definitely get it patched but just like for checkpoint you can buy yourself some time by not exposing these devices to the internet. And today F5 joins the server day group with an actively exploited vulnerability that was patched today for a Big-IP the access policy manager or APM. This only affects devices that are configured as an OAuth authorization server. It's a buffer overflow fromhod attributes that are vain. And this is created a pure willingness to crédit each other or even further needed for an effective Lobby and the trial civil world to improve它的 employees available to each other. We do notice that gensetx available to have an monitored the potential Valparation. This looks like theよろしく guard option and a player of all the actual Eclipse or chaotic Eclipse does deserve at least a little honorable mention for releasing another Windows Defender of vulnerability, even though this one I think is a little bit underwhelming compared to the other vulnerabilities that they discovered. This one essentially just fills up the disk and as a result Windows Defender is not able to download updates. Well, with that, that's it for today. So thanks again for listening. Thanks for liking. Thanks for recommending this podcast and thanks for subscribing and talk to you again tomorrow. Bye.





