Check Point confirms active exploitation of a critical VPN vulnerability patched on September 9. A separate management zero-day requires distinct remediation.

2 points•LebToki•7 days ago•1 comment•

1 comment

LebToki7 days ago
Check Point is warning its users over the active exploitation of CVE-2026-85102, a severe vulnerability in its Security Gateway product. This critical pre-authentication remote code execution flaw exists in the VPNs certificate-handling functionality. According to BleepingComputer , Check Point released a security bulletin confirming that threat actors have been actively exploiting this gap to conduct unauthorized attacks.

Read the full thread on Hacker News →

Related stories