Check Point VPN RCE exploited, admins urged to patch
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of i
What Happened
Check Point has confirmed that attackers are actively exploiting a pre-authentication remote code execution vulnerability tracked as CVE-2026-85102 in the VPN certificate-handling component of its Security Gateway product line. The vendor’s warning follows detection of exploitation attempts against internet-facing gateways, and it marks the second time in under a year that Check Point VPN infrastructure has been targeted at scale.
The flaw resides in how Security Gateway processes certificates during VPN tunnel negotiation. Because the vulnerable code path executes before authentication completes, an unauthenticated attacker with network access to the VPN endpoint can trigger it. Check Point has published patches and mitigation guidance, and it is urging customers to treat internet-exposed gateways as compromised until proven otherwise.
Why It Matters
Check Point Security Gateway sits at the perimeter of thousands of enterprises, government agencies, and managed service providers. A pre-auth RCE on that appliance is effectively a skeleton key: successful exploitation can grant attackers a foothold inside the trusted network before any credential is presented. From there, lateral movement into internal directories, hypervisors, and backup infrastructure becomes a routine follow-on.
Edge-device exploitation has become the preferred initial access vector for ransomware affiliates and state-sponsored intrusion sets alike. Organizations that rely on VPN concentrators as their primary remote-access control plane should assume that exploitation of this class of bug is not hypothetical, particularly given Check Point’s own confirmation of in-the-wild activity.
Technical Details
- CVE: CVE-2026-85102
- Class: Pre-authentication remote code execution
- Component: VPN certificate-handling functionality in Security Gateway
- Vector: Crafted certificate data sent to the exposed VPN service; no credentials required
- Impact: Arbitrary code execution in the context of the gateway service
- Exposure: Any Security Gateway with a VPN blade reachable from the internet
Administrators should inventory gateways by version and hotfix level, then apply the vendor’s fix. Where patching cannot be immediate, restricting VPN access to known IP ranges and enabling the vendor’s recommended inspection controls reduces but does not eliminate exposure. Review gateway logs for anomalous certificate negotiation failures and unexpected process spawning.
Immediate Risk
Severity is critical. Pre-auth RCE on perimeter VPN hardware offers the highest ratio of access to effort for an attacker, and confirmed exploitation means scanning and weaponization are already underway. Expect mass exploitation attempts within days as proof-of-concept details circulate. Organizations with internet-facing gateways that have not patched should prioritize this above nearly all other remediation work, and any gateway showing signs of compromise should be rebuilt rather than cleaned. For related exploitation context, see our prior coverage of Check Point Quantum VPN RCE exploited in the wild.
Security Insight
The recurring lesson here is architectural rather than operational. VPN concentrators have become the single most reliable entry point for sophisticated intrusions precisely because they are simultaneously internet-facing, poorly instrumented, and trusted by default once a tunnel forms. Check Point’s own confirmation of exploitation mirrors the pattern seen with Ivanti, Citrix, and Fortinet edge appliances: the vendor discloses, attackers were already inside, and victims learn of the breach weeks later. The non-obvious takeaway is that patching speed alone will not close this gap. Security teams should treat every VPN gateway as a semi-trusted DMZ host rather than a trusted internal system, segment remote-access traffic accordingly, and log certificate negotiation at full fidelity. Organizations that architect for “assume the gateway is compromised” will detect these intrusions during the dwell phase instead of during incident response.
Further Reading
Never miss a security update
Get real-time security alerts delivered to your preferred platform.
Related News
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chai
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence o
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]