Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Summary

Check Point has confirmed that hackers are actively exploiting a pre-authentication remote code execution (RCE) vulnerability, identified as CVE-2026-85102, within the VPN certificate-handling functionality of its Security Gateway product. This exploitation allows attackers to gain unauthorized access and execute arbitrary code.

IFF Assessment

FOE

The active exploitation of a critical RCE vulnerability allows attackers to compromise systems and execute code, posing a significant threat to defenders.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 25, 2026. Known ransomware use: Unknown.

Defender Context

Organizations using Check Point Security Gateway products need to be immediately aware of this actively exploited RCE vulnerability. Prioritizing patching and implementing compensating controls is crucial to prevent unauthorized access and code execution by threat actors. Monitoring for signs of compromise related to this CVE is essential.

Read Full Story →