The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

Check Point confirmed active exploitation of CVE-2026-85102, a critical pre-authentication remote code execution vulnerability in its Security Gateway VPN certificate-handling functionality, beginning September 12, 2026. Threat actors used anonymizing infrastructure including VPNs and proxies to hide their locations while exploiting the flaw. The Dutch NCSC had previously warned of imminent exploitation on September 10. A second zero-day vulnerability, CVE-2026-93616, affecting the Management web service has been exploited since July 23, allowing script execution and Java class loading. CISA added both flaws to its Known Exploited Vulnerabilities catalog with a September 25 remediation deadline.

This incident highlights the persistent targeting of VPN infrastructure by sophisticated threat actors, reflecting the broader trend of exploiting network perimeter security solutions that became critical during remote work adoption and continue to serve as high-value attack vectors.

Why This Matters Now

VPN infrastructure remains a prime target as organizations maintain hybrid work models, making zero-day exploitation of network security appliances an immediate threat to enterprise perimeters and requiring urgent patching of critical vulnerabilities.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

It's a pre-authentication remote code execution vulnerability in VPN infrastructure, allowing attackers to compromise systems without credentials and potentially gain initial network access.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely have constrained attacker lateral movement and reduced blast radius following the Check Point VPN gateway compromise through segmentation controls and east-west traffic enforcement.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While the initial VPN gateway compromise would likely still occur, CNSF visibility controls may have provided earlier detection of anomalous certificate handling patterns and post-exploitation network behavior.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely have constrained the scope of privilege escalation by limiting administrative access paths and restricting the attacker's ability to gain broader system control beyond the initial compromise point.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have significantly constrained lateral movement by enforcing micro-segmentation policies between network zones and requiring explicit authorization for inter-segment communications from the compromised gateway.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls would likely have detected anomalous outbound connections and suspicious proxy communications, potentially disrupting command and control channel establishment and reducing attacker operational capabilities.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security controls would likely have constrained data exfiltration by enforcing strict outbound traffic policies and detecting unusual data transfer patterns, even through encrypted VPN tunnels.

Impact (Mitigations)

The overall organizational impact would likely be substantially reduced, with compromise limited to specific network segments rather than enterprise-wide access, and faster incident response enabled through improved visibility.

Impact at a Glance

Affected Business Functions

  • Network Security Infrastructure
  • Remote Access Services
  • Site-to-Site VPN Communications
  • Security Management Operations
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: N/A

Data Exposure

Potential unauthorized access to network infrastructure and VPN traffic. Risk of lateral movement within corporate networks and exposure of internal communications and data traversing VPN connections.

Recommended Actions

  • • Implement Inline IPS (Suricata) capabilities to detect and block known exploit patterns like CVE-2026-85102 before they reach vulnerable VPN infrastructure
  • • Deploy Zero Trust Segmentation with least privilege access controls to limit lateral movement even if VPN gateways are compromised
  • • Establish Multicloud Visibility & Control to detect anomalous VPN traffic patterns and repeated malformed certificate requests indicative of exploitation attempts
  • • Enable Egress Security & Policy Enforcement to prevent data exfiltration through compromised VPN tunnels and unauthorized outbound connections
  • • Deploy Cloud Native Security Fabric (CNSF) for real-time inspection and autonomous threat response to prevent pre-authentication vulnerabilities from being successfully exploited

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image