Close Menu
NCIJ Network NCIJ Network
    What's Hot

    BlackRock sees a new $5 trillion AI trade emerging for stablecoins

    September 23, 2026

    US contractors reportedly purchase tin from company accused of illegal Amazon mining

    September 23, 2026

    Picking a side on Ed Sheeran, Israel and Palestine | Ed Sheeran

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • BlackRock sees a new $5 trillion AI trade emerging for stablecoins
    • US contractors reportedly purchase tin from company accused of illegal Amazon mining
    • Picking a side on Ed Sheeran, Israel and Palestine | Ed Sheeran
    • Did Denmark play ‘Send in the Clowns’ when Rubio arrived at Greenland deal ceremony?
    • No, this video doesn’t disprove the 9/11 attack on the south tower of the World Trade Center
    • A huit mois de la présidentielle, les comptes de campagne déjà sous surveillance – POLITICO
    • Burnham brands ban on football fans drinking alcohol in stands as ‘discrimination’
    • Tories would prevent long-term jobless spending benefits on alcohol and cigarettes
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 23, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product.

    The same advisory also warns of threat actors exploiting a pre-authentication path traversal flaw tracked as CVE-2026-93616, which impacts the Management web service and can allow script execution and Java class loading.

    The company says that CVE-2026-93616 has been exploited as a zero-day since July 23.

    On September 10, the Dutch Nationaal Cyber Security Centrum (NCSC) alerted of the Security Gateway issue and urged users to apply available security updates as imminent exploitation was expected.

    Check Point has now confirmed that malicious activity started on September 12, with attackers using VPNs and proxies to hide their location.

    “Starting September 12, 2026, we observed a wave of exploitation attempts against Spark customers,” reads Check Point’s alert.

    “The attempts originated from anonymization infrastructure, including VPN services and proxies,” the company said, adding that certificates with the following subjects were used:

    • CN=vpn,OU=users,O=global
    • CN=vpn-user,OU=users,O=global
    • CN=vpnuser,OU=users,O=global

    However, the cybersecurity company noted that the three subjects only reflect current observations and more may be in use.

    CISA has now added the two flaws in its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to apply the available fixes and/or mitigations by September 25, 2026.

    Mitigating the risk

    Check Point’s advisory on CVE-2026-85102 recommends that administrators install Check Point LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways, or install a fixed Jumbo Hotfix: R81.20 Take 166, R82 Take 126, R82.10 Take 44, or R81.10 Take 190, or later.

    Customers should also update Spark firewalls to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later.

    System administrators are advised to verify if LivePatch is active by running the cpinfo -y CPupdates command on the Security Gateway  in expert mode.

    The advisory specifically warns that some customers who installed an earlier offline LivePatch package need Take 26 for full coverage.

    If updating isn’t possible, it is recommended to disable the VPN implied rules and create explicit rules that restrict Site-to-Site VPN on UDP/500 and UDP/4500 to specific peer IP addresses.

    For Remote Access VPN, allow only the required services over UDP/500, UDP/4500, TCP/443, and TCP/80 where applicable, and restrict source client IP ranges where possible.

    Check Point notes that these mitigation measures do not apply to locally managed Spark firewalls.

    For mitigation and hunting advice for the Management web service CVE-2026-93616, Check Point points to this support article.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    check exploiting Flaw gateway hackers Point RCE Security VPN warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

    UK shares findings of damning climate crisis national security report suppressed under Starmer | Climate crisis

    A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

    Adobe Patches Critical Flaws in Connect, AEM Forms

    Hackers Say They Stole Thousands of Sensitive F.B.I. Personnel Records

    MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    BlackRock sees a new $5 trillion AI trade emerging for stablecoins

    September 23, 2026

    US contractors reportedly purchase tin from company accused of illegal Amazon mining

    September 23, 2026

    Picking a side on Ed Sheeran, Israel and Palestine | Ed Sheeran

    September 23, 2026

    Did Denmark play ‘Send in the Clowns’ when Rubio arrived at Greenland deal ceremony?

    September 23, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    BlackRock sees a new $5 trillion AI trade emerging for stablecoins

    September 23, 2026

    US contractors reportedly purchase tin from company accused of illegal Amazon mining

    September 23, 2026

    Picking a side on Ed Sheeran, Israel and Palestine | Ed Sheeran

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.