Podcast Detail

SANS Stormcast Wednesday, September 23rd, 2026: GET with Body; Checkpoint, VeloCloud, BigIP and Microsoft Defender 0-days

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10106.mp3

Podcast Logo
GET with Body; Checkpoint, VeloCloud, BigIP and Microsoft Defender 0-days
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

The Truth about GET and HTTP Standards
https://isc.sans.edu/diary/The%20Truth%20about%20GET%20and%20HTTP%20Standards/33358

CVE-2026-93616: 0-Day Remote Code Execution Vulnerability patch in Checkpoint Management Server
https://support.checkpoint.com/results/sk/sk1000171/

VeloCloud Orchestrator (VCO) Patch for Exploited Vulnerability CVE-2026-93952
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183

F5 BigIP APM Exploited Vulnerability Patched CVE-2026-94127
https://my.f5.com/manage/s/article/K000162605

My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich

Podcast Transcript

 Hello and welcome to the Wednesday, September 22, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from Las
 Vegas, Nevada. And this episode is brought to you by
 the SANS.edu Graduate Certificate Program in Cyber
 Defense Operations. I brought a diary today a little bit as
 a follow up to what Xavier wrote on Friday about the
 query method in HTTP that was recently introduced just to
 look into hey what actually happens when you send a body
 with the GET request. Well it turns out that the RFC weren't
 always very specific about what to do in this case and as
 a result it really varies a little bit by web server.
 Apache actually is perfectly fine with a body as part of a
 GET request. Most other web servers will just ignore it
 even if you send a content length header. Now one that
 actually sends an error back is lighthttpd. That's a web
 server you often see sort of in IoT devices. But as of a
 rule of thumb the body is just ignored and no errors being
 sent back. It's basically just treated like a GET request
 without the body. Well today we got a couple of series to
 talk about. First of his vulnerability that's already
 being exploited against the checkpoint management server.
 This is an arbitrary code execution vulnerability. It's
 one of those file upload issues where an attacker is
 able to exploit a directory traversal vulnerability to
 upload a file that then can be used to execute arbitrary
 code. A patch has been released today in the form of
 a hotfix. So please apply it. Apply it quickly. Yes the
 management server should not be exposed to the internet but
 this would still be an extremely juicy opportunity
 for some lateral movement for an attacker. So definitely
 this will will soon be attacked more widely. And
 Arista released an advisory patching an actively exploited
 vulnerability for VeloCloud orchestrator. This affects the
 on premise version and has a CVSS version 3.1 base score of
 10 and version 4.0 base score of 9.5. The advisor is a
 little bit vague here what exactly is happening. But
 given the CVSS score and the and stating that the remote
 attacker that has access to this vulnerability may exploit
 it to compromise the confidentiality, integrity and
 availability of the orchestrator. So I would
 probably call this a code execution vulnerability.
 Definitely get it patched but just like for checkpoint you
 can buy yourself some time by not exposing these devices to
 the internet. And today F5 joins the server day group
 with an actively exploited vulnerability that was patched
 today for a Big-IP the access policy manager or APM. This
 only affects devices that are configured as an OAuth
 authorization server. It's a buffer overflow
 fromhod attributes that are vain. And this is created a
 pure willingness to crédit each other or even further
 needed for an effective Lobby and the trial civil world to
 improve它的 employees available to each other. We do notice
 that gensetx available to have an monitored the potential
 Valparation.
 This looks like theよろしく guard option and a player of all the
 actual Eclipse or chaotic Eclipse does deserve at least
 a little honorable mention for releasing another Windows
 Defender of vulnerability, even though this one I think
 is a little bit underwhelming compared to the other
 vulnerabilities that they discovered. This one
 essentially just fills up the disk and as a result Windows
 Defender is not able to download updates. Well, with
 that, that's it for today. So thanks again for listening.
 Thanks for liking. Thanks for recommending this podcast and
 thanks for subscribing and talk to you again tomorrow.
 Bye.