Tech News
← Home  ·  All topics

Cve 2026 85102

2 GoKawiil briefs on this topic

Check Point confirms active exploitation of two VPN gateway flaws

Check Point disclosed that hackers are actively exploiting CVE-2026-85102, a pre-authentication remote code execution flaw in its Security Gateway VPN certificate handling, and CVE-2026-93616, a path traversal bug in its Management web service. The company says the path traversal flaw has been exploited as a zero-day since July 23, while exploitation of the gateway flaw began September 12 using VPNs and proxies to mask attacker origin. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 25, 2026 to patch.

Dutch NCSC warns Check Point VPN flaws face imminent exploitation

The Dutch NCSC has issued an alert about two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, warning that attacks exploiting them are likely to begin soon even though no public proof-of-concept exploit exists yet. Check Point released patches for both bugs on September 9, covering Security Gateways and Management Servers across multiple supported and end-of-support versions.