Executive Summary
Check Point confirmed active exploitation of CVE-2026-85102, a critical pre-authentication remote code execution vulnerability in its Security Gateway VPN certificate-handling functionality, beginning September 12, 2026. Threat actors used anonymizing infrastructure including VPNs and proxies to hide their locations while exploiting the flaw. The Dutch NCSC had previously warned of imminent exploitation on September 10. A second zero-day vulnerability, CVE-2026-93616, affecting the Management web service has been exploited since July 23, allowing script execution and Java class loading. CISA added both flaws to its Known Exploited Vulnerabilities catalog with a September 25 remediation deadline.
This incident highlights the persistent targeting of VPN infrastructure by sophisticated threat actors, reflecting the broader trend of exploiting network perimeter security solutions that became critical during remote work adoption and continue to serve as high-value attack vectors.
Why This Matters Now
VPN infrastructure remains a prime target as organizations maintain hybrid work models, making zero-day exploitation of network security appliances an immediate threat to enterprise perimeters and requiring urgent patching of critical vulnerabilities.
Attack Path Analysis
Attackers exploited CVE-2026-85102, a pre-authentication RCE vulnerability in Check Point Security Gateway VPN certificate-handling functionality, gaining initial access starting September 12, 2026. Following successful exploitation, attackers likely escalated privileges through the compromised gateway, moved laterally within the network infrastructure, established command and control channels using VPNs and proxies for anonymization, exfiltrated sensitive data through compromised VPN tunnels, and potentially caused operational disruption to critical network infrastructure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-85102, a pre-authentication remote code execution vulnerability in Check Point Security Gateway VPN certificate-handling functionality, using crafted certificates with subjects like CN=vpn,OU=users,O=global to gain initial access without authentication.
Related CVEs
CVE-2024-24919
CVSS 8.6A pre-authentication remote code execution vulnerability in Check Point Security Gateway VPN certificate-handling functionality allows unauthenticated attackers to execute arbitrary code.
Affected Products:
Check Point Security Gateway – R81.10, R81.20, R82, R82.10
Exploit Status:
exploited in the wildCVE-2024-24920
CVSS 7.8A pre-authentication path traversal vulnerability in Check Point Management web service allows attackers to execute scripts and load Java classes without authentication.
Affected Products:
Check Point Management Server – R81.10, R81.20, R82
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Process Injection
Command and Scripting Interpreter: Unix Shell
Proxy
Valid Accounts
Exploitation for Privilege Escalation
Remote System Discovery
Exploitation of Remote Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.08
DORA – Patch Management
Control ID: Art. 11
CISA ZTMM 2.0 – Network Environment Encryption
Control ID: Networks 3
NIS2 Directive – Cybersecurity Risk Management
Control ID: Art. 21.2(a)
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.8.8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
Critical VPN RCE vulnerability exploitation targeting Check Point Security Gateways creates severe trust erosion and regulatory compliance failures for security providers.
Financial Services
Pre-authentication RCE flaws in VPN infrastructure enable unauthorized access to financial networks, threatening PCI compliance and encrypted transaction security.
Health Care / Life Sciences
Exploited VPN vulnerabilities compromise HIPAA-mandated encryption controls, exposing patient data transmission and violating healthcare privacy regulations through lateral movement.
Government Administration
Active exploitation of Check Point VPN flaws threatens federal agency networks, prompting CISA KEV catalog inclusion with mandatory remediation deadlines.
Sources
- Check Point warns of hackers exploiting Security Gateway VPN RCE flawhttps://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/Verified
- Check Point Security Advisory - CVE-2024-24919 and CVE-2024-24920 Active Exploitationhttps://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2024-24919-and-cve-2024-24920/Verified
- CISA Known Exploited Vulnerabilities Catalog - Check Point Security Gatewayhttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- Dutch NCSC Alert - Critical Check Point VPN Vulnerabilitieshttps://www.ncsc.nl/actueel/advisory?id=NCSC-2024-0305Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained attacker lateral movement and reduced blast radius following the Check Point VPN gateway compromise through segmentation controls and east-west traffic enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While the initial VPN gateway compromise would likely still occur, CNSF visibility controls may have provided earlier detection of anomalous certificate handling patterns and post-exploitation network behavior.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have constrained the scope of privilege escalation by limiting administrative access paths and restricting the attacker's ability to gain broader system control beyond the initial compromise point.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have significantly constrained lateral movement by enforcing micro-segmentation policies between network zones and requiring explicit authorization for inter-segment communications from the compromised gateway.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely have detected anomalous outbound connections and suspicious proxy communications, potentially disrupting command and control channel establishment and reducing attacker operational capabilities.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely have constrained data exfiltration by enforcing strict outbound traffic policies and detecting unusual data transfer patterns, even through encrypted VPN tunnels.
The overall organizational impact would likely be substantially reduced, with compromise limited to specific network segments rather than enterprise-wide access, and faster incident response enabled through improved visibility.
Impact at a Glance
Affected Business Functions
- Network Security Infrastructure
- Remote Access Services
- Site-to-Site VPN Communications
- Security Management Operations
Estimated downtime: 3 days
Estimated loss: N/A
Potential unauthorized access to network infrastructure and VPN traffic. Risk of lateral movement within corporate networks and exposure of internal communications and data traversing VPN connections.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Inline IPS (Suricata) capabilities to detect and block known exploit patterns like CVE-2026-85102 before they reach vulnerable VPN infrastructure
- • Deploy Zero Trust Segmentation with least privilege access controls to limit lateral movement even if VPN gateways are compromised
- • Establish Multicloud Visibility & Control to detect anomalous VPN traffic patterns and repeated malformed certificate requests indicative of exploitation attempts
- • Enable Egress Security & Policy Enforcement to prevent data exfiltration through compromised VPN tunnels and unauthorized outbound connections
- • Deploy Cloud Native Security Fabric (CNSF) for real-time inspection and autonomous threat response to prevent pre-authentication vulnerabilities from being successfully exploited



