Story thread · 2 reports / 2 sources
The VPN Certificate Bypass That Was Patched in September Is Now Actively Exploited — Federal Deadline Hits Sep 25
forkast.news · 14h · first report
CVE-2026-85102, a critical improper certificate validation vulnerability (CWE-295) affecting the VPN negotiation flow of Check Point Security Gateways and Spark Firewalls, is now confirmed to be under active exploitation — three days before a federal compliance deadline. The vulnerability was initially disclosed on September 9, 2026, with patches made available immediately. At the time, Check […]
The coverage
- Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
bleepingcomputer.com · 8h
The conversation · 0
Sign in to join the conversation.
No comments yet — start the thread.