Cybersecurity company Check Point confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution vulnerability in Security Gateway VPN certificate handling, as of 2026-09-24. The firm warned administrators to patch immediately or apply workarounds.
5 reportsother · tech
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. https://www. bleepingcomputer.com/news/secu rity/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/
Check Point confirms active exploitation of CVE-2026-85102, unauthenticated RCE in Security Gateway VPN negotiation, and CVE-2026-93616, path traversal leading to script execution on management systems. Internet-exposed gateways and management planes should be patched and reviewed for compromise immediately. # CheckPoint # ThreatIntel # VpnSecurity https:// cyberworldops.eu/en/active-att acks-turn
🤖 CVE-2026-85102: pre-auth RCE in Check Point Security Gateway VPN certificate handling, confirmed actively exploited in the wild. Check Point warns of attacks; apply the hotfix or workaround to exposed gateways now. 🔗 https://www. bleepingcomputer.com/news/secu rity/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/ # CVE # RCE # CyberSec