bleeping-computer · Crawled Sep 24, 2026

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

3 IoCs
Read original article ↗

AI Summary

Check Point has confirmed active exploitation of two critical vulnerabilities in its Security Gateway product: CVE-2026-85102, a pre-authentication remote code execution flaw in the VPN certificate-handling functionality, and CVE-2026-93616, a pre-authentication path traversal vulnerability in the Management web service. Exploitation of CVE-2026-93616 began as a zero-day on July 23, 2026, and widespread attacks on CVE-2026-85102 started on September 12, with threat actors using anonymizing infrastructure such as VPNs and proxies. The U.S. CISA has added both flaws to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by September 25, 2026.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
Filename CN=vpn,OU=users,O=global Details →
Filename CN=vpn-user,OU=users,O=global Details →
Filename CN=vpnuser,OU=users,O=global Details →