Check Point Warns of Active Exploitation of Two Critical VPN and Management Flaws
Check Point Software Technologies has issued an urgent advisory after confirming that threat actors are actively exploiting two newly disclosed vulnerabilities in its flagship VPN gateway and Security Management suites. The firm said the attacks are ongoing and that the flaws, identified as CVE-2026-85102 and CVE-2026-93616, carry a maximum CVSS rating of 9.8, placing them among the most severe security issues discovered this year.
CVE-2026-85102 targets the VPN gateway component that many enterprises rely on to provide remote access for employees and partners. The flaw permits unauthenticated attackers to execute arbitrary code on the appliance, effectively bypassing the encryption and authentication layers that are supposed to protect inbound traffic. The second vulnerability, CVE-2026-93616, resides in the Security Management console used to configure and monitor Check Point devices; it also enables remote code execution without requiring valid credentials.
Both vulnerabilities are classified as zero‑day exploits, meaning that they were being weaponised before public patches were available. According to Check Point, the attack chain can be triggered simply by sending specially crafted packets to the vulnerable services, after which the malicious payload can gain full control of the underlying operating system. In practice, this gives adversaries the ability to move laterally across corporate networks, exfiltrate data, or install additional malware.
The disclosure arrives at a time when VPN infrastructure has become a frequent target for cyber‑criminals, especially after the surge in remote work prompted by the pandemic. High‑profile incidents such as the 2022 Log4j exploitation and the 2023 SolarWinds supply‑chain breach have underscored how critical network entry points can be weaponised at scale. Security analysts note that attackers are increasingly seeking out unpatched or misconfigured VPN devices to establish footholds in otherwise well‑defended environments.
In response, Check Point has released emergency patches for both the VPN gateway and the Management console, and it is urging customers to apply the updates without delay. The company also recommends disabling any unnecessary remote‑access features, enforcing strong multi‑factor authentication, and closely monitoring network traffic for anomalous activity that could indicate an ongoing compromise. Organizations that cannot patch immediately are advised to place the affected systems behind additional firewalls or intrusion‑prevention devices.
Looking ahead, industry observers expect that the disclosure will prompt a wave of scanning activity as threat actors hunt for unpatched installations. The rapid exploitation observed by Check Point suggests that the vulnerabilities were likely sold on underground markets shortly after discovery. Security teams are therefore advised to verify their patch status, review audit logs for signs of suspicious connections, and consider broader risk‑mitigation strategies such as zero‑trust network architectures. The episode serves as a reminder that even mature security vendors can harbor critical flaws, and that continuous vigilance remains essential for protecting corporate networks.
Comments (0)
Be the first to comment.
Join the discussion