Critical Check Point VPN vulnerabilities face imminent exploitation

Check Point patched two critical VPN vulnerabilities (CVE-2026-85102 and CVE-2026-85103) with CVSS scores of 9.8 that allow unauthenticated remote code execution in Security Gateway and Management Server products. As of September 14, 2026, the Dutch NCSC warned that exploitation of the flaws was imminent, prompting urgent action for internet-facing VPN gateway administrators.

20 reportsother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 Check Point research team has identified and remediated two critical VPN-related vulnerabilities, C

mastodon:infosec-exchangeother20d ago kagi ↗

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of a

Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateway

mastodon:infosec-exchangeother19d ago kagi ↗

Check Point patched two critical VPN certificate handling flaws, CVE-2026-85102 and CVE-2026-85103, both rated 9.8. They allow unauthenticated remote code execution, making internet-facing VPN gateways an immediate target. Review exposure, apply patches, and investigate for signs of compromise. # CyberSecurity # CheckPoint # VPN # RCE https:// cyberworldops.eu/en/check-poin t-patches-two-critical-

⚠️ Threat Notice: Check Point VPN Vulnerabilities ⚠️ Check Point has patched two critical vulnerabilities affecting VPN certificate handling in its Security Gateway and Security Management Server prod

mastodon:infosec-exchangeother19d ago kagi ↗

⚠️ Threat Notice: Check Point VPN Vulnerabilities ⚠️ Check Point has patched two critical vulnerabilities affecting VPN certificate handling in its Security Gateway and Security Management Server products, either of which could allow an unauthenticated attacker to achieve remote code execution. Check Point discovered both vulnerabilities internally and reports no indication of active exploitation

CVE-2026-85102 | 9.8 Critical | Authentication Bypass and Remote Code Execution → An unauthenticated attacker can exploit a certificate trust validation failure during VPN negotiation to execute code

mastodon:infosec-exchangeother19d ago kagi ↗

CVE-2026-85102 | 9.8 Critical | Authentication Bypass and Remote Code Execution → An unauthenticated attacker can exploit a certificate trust validation failure during VPN negotiation to execute code on the Security Gateway. CVE-2026-85103 | 9.8 Critical | Heap-Based Buffer Overflow in Certificate Decoding → An unauthenticated attacker can exploit a heap-based buffer overflow that occurs while the

Two critical CSF plugin vulnerabilities, CVE-2026-65638 and CVE-2026-65639, allow remote code execution. Patch your ConfigServer firewall immediately. # CSFPlugin # Cybersecurity # CVE202665639 # Vuln

mastodon:infosec-exchangeother18d ago kagi ↗

Two critical CSF plugin vulnerabilities, CVE-2026-65638 and CVE-2026-65639, allow remote code execution. Patch your ConfigServer firewall immediately. # CSFPlugin # Cybersecurity # CVE202665639 # Vulnerabilities # InfoSec https:// securityonline.info/csf-plugin -vulnerabilities-cvss-9-5/?utm_source=mastodon&utm_medium=jetpack_social

Check Point Patches Critical VPN Certificate Flaws Enabling Unauthenticated RCE Check Point patched two critical 9.8-rated vulnerabilities in its VPN certificate handling that allow unauthenticated re

mastodon:infosec-exchangeother18d ago kagi ↗

Check Point Patches Critical VPN Certificate Flaws Enabling Unauthenticated RCE Check Point patched two critical 9.8-rated vulnerabilities in its VPN certificate handling that allow unauthenticated remote code execution. The flaws affect Security Gateways, Management Servers, and Spark Firewalls across multiple versions. **If you use Check Point Quantum Gateways, Security Management Servers, or Sp

Check Point patches two critical VPN flaws (CVSS 9.8) enabling unauthenticated RCE, its third critical alert in four months. End-of-Support versions https:// deafnews.it/en/article/check-p oint-sounds

mastodon:infosec-exchangeother18d ago kagi ↗

Check Point patches two critical VPN flaws (CVSS 9.8) enabling unauthenticated RCE, its third critical alert in four months. End-of-Support versions https:// deafnews.it/en/article/check-p oint-sounds-third-critical-alert-in-four-months-two-vpn-flaws-enable-unauthenticated-rce

🚨 Two VLC Media Player flaws can allow code execution and leak sensitive memory Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23. ⠀ CVE

mastodon:infosec-exchangeother18d ago kagi ↗

🚨 Two VLC Media Player flaws can allow code execution and leak sensitive memory Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23. ⠀ CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation. An attacker can craft a malicious PNG with manipulated dimensions that causes VL

Critical ConfigServer Firewall Flaw Allows Unauthenticated Remote Command Execution ConfigServer Security & Firewall (CSF) patched a critical shell injection vulnerability (CVE-2026-65638) in its MESS

mastodon:infosec-exchangeother17d ago kagi ↗

Critical ConfigServer Firewall Flaw Allows Unauthenticated Remote Command Execution ConfigServer Security & Firewall (CSF) patched a critical shell injection vulnerability (CVE-2026-65638) in its MESSENGER service that allows unauthenticated remote code execution. **If you run ConfigServer Security & Firewall (CSF) on your Linux or cPanel/WHM servers, update to version 16.30 right away (on cPanel

Google Patches 26 Critical Vulnerabilities in September 2026 Android Security Update Google's September 2026 Android Security Bulletin patches over 90 vulnerabilities, including 26 critical flaws that

mastodon:infosec-exchangeother17d ago kagi ↗

Google Patches 26 Critical Vulnerabilities in September 2026 Android Security Update Google's September 2026 Android Security Bulletin patches over 90 vulnerabilities, including 26 critical flaws that allow remote code execution and privilege escalation across Android versions 14 to 17. **After several quiet months, September patch fixes a bunch of critical flaws and a huge list of patches. Most u

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. https://www. bleepingcomput

mastodon:infosec-exchangeother17d ago kagi ↗

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. https://www. bleepingcomputer.com/news/secu rity/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/

https://www. ncsc.nl/alerts/kritieke-kwetsb aarheden-in-check-point-vpn-producten-met-actief-misbruik-verwacht-update-nu Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerke

mastodon:infosec-exchangeother17d ago kagi ↗

https://www. ncsc.nl/alerts/kritieke-kwetsb aarheden-in-check-point-vpn-producten-met-actief-misbruik-verwacht-update-nu Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en verwacht dat er snel po

🤖 Dutch NCSC warns of imminent exploitation of two critical Check Point VPN flaws. CVE-2026-85102: cert validation issue, RCE on Security Gateway. CVE-2026-85103: heap overflow in VPN cert ASN.1 deco

mastodon:infosec-exchangeother17d ago kagi ↗

🤖 Dutch NCSC warns of imminent exploitation of two critical Check Point VPN flaws. CVE-2026-85102: cert validation issue, RCE on Security Gateway. CVE-2026-85103: heap overflow in VPN cert ASN.1 decoder, RCE. No public PoC yet; fixes shipped Sep 9. Patch now. 🔗 https://www. bleepingcomputer.com/news/secu rity/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/ # CVE # VPN # Cyber

🚨 Check Point has patched two critical vulnerabilities in its VPN infrastructure, and both carry a CVSS score of 9.8. CVE-2026-85102 and CVE-2026-85103 affect the pre-authentication VPN attack surfac

mastodon:infosec-exchangeother16d ago kagi ↗

🚨 Check Point has patched two critical vulnerabilities in its VPN infrastructure, and both carry a CVSS score of 9.8. CVE-2026-85102 and CVE-2026-85103 affect the pre-authentication VPN attack surface and can lead to unauthenticated remote code execution. CVE-2026-85102 involves certificate trust validation, while CVE-2026-85103 is a heap-based overflow triggered during ASN.1 certificate parsing.

VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt

mastodon:infosec-exchangeother16d ago kagi ↗

VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams. **If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN

⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing im

mastodon:infosec-exchangeother16d ago kagi ↗

⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with… https:// threatnoi