Check Point confirms active exploitation of two VPN gateway flaws
Check Point disclosed that hackers are actively exploiting CVE-2026-85102, a pre-authentication remote code execution flaw in its Security Gateway VPN certificate handling, and CVE-2026-93616, a path traversal bug in its Management web service. The company says the path traversal flaw has been exploited as a zero-day since July 23, while exploitation of the gateway flaw began September 12 using VPNs and proxies to mask attacker origin. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 25, 2026 to patch.
GoKawiil's interpretation of the reporting above, not reported fact.
The dual exploitation of a pre-auth RCE and a zero-day path traversal flaw in widely deployed VPN infrastructure suggests attackers had a substantial head start before public disclosure, potentially exposing enterprise networks that rely on Check Point gateways for perimeter security. The use of anonymization infrastructure indicates coordinated, possibly persistent campaigns rather than opportunistic scanning, which could complicate attribution and incident response for affected organizations.
- Two Check Point flaws, CVE-2026-85102 and CVE-2026-93616, are being actively exploited in the wild.
- One flaw was exploited as a zero-day since July 23, well before patches were widely applied.
- CISA has mandated federal agencies patch or mitigate both vulnerabilities by September 25, 2026.
Source: bleepingcomputer.com, 2026-09-23
Published there as: “Check Point warns of hackers exploiting Security Gateway VPN RCE flaw”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.