Story thread · 2 reports / 2 sources

The VPN Certificate Bypass That Was Patched in September Is Now Actively Exploited — Federal Deadline Hits Sep 25

forkast.news · 14h · first report

CVE-2026-85102, a critical improper certificate validation vulnerability (CWE-295) affecting the VPN negotiation flow of Check Point Security Gateways and Spark Firewalls, is now confirmed to be under active exploitation — three days before a federal compliance deadline. The vulnerability was initially disclosed on September 9, 2026, with patches made available immediately. At the time, Check […]

The coverage

  1. Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

    bleepingcomputer.com · 8h

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.