Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Check Point has confirmed active exploitation of CVE-2026-85102 and CVE-2026-93616, with attackers using VPNs and proxies to hide their origin while targeting Security Gateway and Management web service flaws. CISA has added both vulnerabilities to its KEV catalog, and Check Point has issued patching and mitigation guidance for affected customers. #CVE-2026-85102 #CVE-2026-93616 #CheckPoint #NCSC #CISA

Keypoints

  • Check Point confirmed active exploitation of CVE-2026-85102 in Security Gateway.
  • CVE-2026-93616 has been exploited as a zero-day since July 23.
  • Attackers used VPNs and proxies to conceal their location.
  • CISA added both flaws to its Known Exploited Vulnerabilities catalog.
  • Check Point issued patching and mitigation steps for affected gateways and Spark firewalls.

Read More: https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/