Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Executive Summary

Check Point reports that attackers are actively exploiting CVE-2026-85102, a pre‑authentication remote code execution flaw in the VPN certificate‑handling of its Security Gateway product. The vulnerability allows attackers to execute arbitrary code on affected devices before authentication, potentially compromising network infrastructure. The company urges customers to apply the latest security patch and monitor for suspicious activity.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-23T19:53:54+00:00 - Category: threat-intel

Original Description: Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]

"The important thing is this: to be able at any moment to sacrifice what we are for what we could become."

— Charles Dubois
Source: Bleeping Computer