Back to Blog

Check Point VPN Flaws Actively Exploited: Why CISA Now Demands Forensic Triage

News By Ali Ghanavati

Check Point VPN Vulnerabilities Under Active Attack

Two critical Check Point VPN vulnerabilities — CVE-2026-85102 and CVE-2026-85103 — are now being actively exploited by attackers, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has taken the unusual step of requiring not just patching but full forensic triage of affected devices. Both flaws carry a CVSS score of 9.8 out of 10, the highest severity tier, and require no authentication to exploit. In practical terms, an attacker on the open internet can compromise a vulnerable VPN gateway without needing any credentials at all.

The escalation from "patch immediately" to "assume you may already be compromised" marks a significant shift that has implications beyond Check Point customers. This is Check Point's fourth critical VPN-related vulnerability disclosed in 2026, and it fits a broader pattern: enterprise VPN infrastructure — from Fortinet's FortiGate devices to Cisco ASA appliances — has become the most-targeted attack surface of the year. Whether you manage enterprise firewalls or simply use a VPN service for personal privacy, the security of VPN gateway infrastructure is now a first-order concern.

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 · Known Exploited Vulnerabilities Catalog · Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

What the Two Flaws Actually Do

The two vulnerabilities target different components of Check Point's VPN implementation, but both allow unauthenticated remote code execution (RCE) — meaning an attacker can run arbitrary commands on the device without logging in.

  • CVE-2026-85102 stems from improper validation of certificate trust during VPN negotiation. When a Check Point Security Gateway or Spark Firewall processes an incoming VPN connection, it parses the connecting party's certificate. A crafted, malicious certificate can bypass trust checks and allow the attacker to execute code on the gateway itself.
  • CVE-2026-85103 is a heap-based buffer overflow in the ASN.1 decoder that parses VPN certificates. This affects a wider range of products, including the Security Management Server in addition to the Security Gateway and Spark Firewall.

Both flaws affect Check Point versions R81.20, R82, R82.10, R81.10.x, and R82.00.x, as well as end-of-support versions from R80 through R81.10. Crucially, there are no workarounds that fully remediate either vulnerability — patching with the vendor's hotfix is the only complete fix.

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 · Check Point CVE-2026-85102 — CVSS 9.8 Unauthenticated RCE · Active Exploitation Imminent: Two Critical Check Point Flaws (CVE-2026-85102, CVE-2026-85103) Allow Unauthenticated Remote Code Execution on VPN-Enabled Security Gateways and Management Appliances

How the Exploitation Escalated: A Timeline

The speed at which these vulnerabilities moved from disclosure to active exploitation is a cautionary lesson in how quickly threat actors weaponize VPN flaws:

  1. September 9, 2026: Check Point disclosed both CVEs and began rolling out emergency hotfixes through its community advisory channel.
  2. September 10: The Dutch National Cyber Security Centre (NCSC) issued a public alert urging immediate patching and warning that exploitation was expected imminently.
  3. September 12: Check Point confirmed that malicious activity had already begun, with attackers using VPNs and proxies to obscure their origin.
  4. September 22: CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog and gave federal civilian agencies just three days — until September 25 — to address the flaws under Binding Operational Directive 26-04.
  5. October 3: Hive Security published a detailed advisory confirming ongoing active exploitation across both the VPN gateway and management interfaces.
  6. October 8: CISA's KEV catalog was updated again, with new entries requiring forensic triage and a compliance deadline of October 11.

The three-day window from September 12 to September 15 — between first confirmed exploitation and the broader security community's response — likely gave attackers a head start against organizations that had not yet patched.

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 · Known Exploited Vulnerabilities Catalog · Check Point warns of hackers exploiting Security Gateway VPN RCE flaw · Check Point VPN and Management Flaws Under Attack: Patch Two Different Trust Boundaries — Hive Security

Why Forensic Triage, Not Just Patching?

CISA's requirement for forensic triage rather than simple patching reflects a hard-learned lesson: once a VPN gateway has been exposed to an unauthenticated RCE flaw, installing the update closes the door but doesn't tell you whether someone already walked through it.

Forensic triage means organizations should actively search their affected devices for indicators of compromise — unexpected processes, new user accounts, altered configurations, or outbound connections to unfamiliar infrastructure. This is a higher bar than routine patching and signals that CISA considers the risk of existing breaches to be substantial.

This approach is consistent with how the agency handled earlier Check Point VPN exploitation this year. CVE-2026-50751, an IKEv1 protocol flaw patched in the summer, was linked to at least one confirmed case involving a Qilin ransomware affiliate. That incident showed that VPN gateway compromise can serve as a direct entry point for ransomware deployment deeper inside a network.

Patch Critical Check Point VPN Vulnerability (CVE-2026-50751)- Check Point Blog · Known Exploited Vulnerabilities Catalog · Check Point VPN Bug CVE-2026-85102 Exploited in the Wild, Forensic Checks Ordered

A Pattern Across the VPN Industry in 2026

These Check Point flaws are not isolated. The year 2026 has seen a striking concentration of critical vulnerabilities in enterprise VPN and firewall products across multiple vendors:

  • Fortinet: The FortiBleed campaign exploited weak or stolen credentials on FortiGate devices, prompting an FBI and Secret Service advisory that remains active.
  • Cisco: A denial-of-service vulnerability in Cisco ASA's Remote Access SSL VPN was disclosed earlier this year, affecting organizations relying on Cisco firewalls for remote connectivity.
  • Check Point: Including the current pair, the company has now disclosed four critical VPN-related CVEs in 2026 alone.

The common thread is that VPN gateways are internet-facing by design. Unlike internal servers protected by layers of network segmentation, a VPN endpoint must be reachable from the public internet — which makes any unpatched flaw a direct path into an organization's internal network. As researchers at the Cloud Security Alliance noted, these flaws demonstrate that VPN infrastructure itself has become the perimeter, and its security posture deserves the same scrutiny as any public-facing web application.

Cisco Security Advisory: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability · Check Point VPN Flaws: Unauthenticated RCE Exploitation Imminent · Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Practical Steps for Organizations and VPN Users

Whether you manage enterprise firewalls or rely on a VPN service for personal use, there are concrete actions worth taking now:

If You Run Check Point Products

  • Apply the hotfixes for CVE-2026-85102 and CVE-2026-85103 immediately if you have not already done so. No workaround substitutes for the patch.
  • Conduct forensic triage on every exposed device, looking for signs of compromise that may have occurred before patching.
  • Audit for deprecated protocols like IKEv1, which were the target of the earlier CVE-2026-50751 exploitation.
  • Review whether end-of-support versions (R80 through R81.10) are still in use, as these are affected but may not receive ongoing support.

If You Use a VPN Service

  • Ask your provider whether they use Check Point, Fortinet, or Cisco appliances and whether those devices are fully patched.
  • Remember that VPN security depends on the infrastructure behind the connection, not just the encrypted tunnel itself. As we explored in our coverage of VPN-over-DNS traffic, a working connection and a truly private one are not always the same thing.
  • For teams relying on VPN for business connectivity, verify that your provider's gateway patching cadence meets your risk tolerance.

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 · Known Exploited Vulnerabilities Catalog · Active Exploitation Imminent: Two Critical Check Point Flaws (CVE-2026-85102, CVE-2026-85103) Allow Unauthenticated Remote Code Execution on VPN-Enabled Security Gateways and Management Appliances

The Bigger Lesson: VPN Infrastructure Is Now the Attack Surface

The ongoing exploitation of Check Point VPN vulnerabilities underscores a fundamental shift in how network security threats are evolving. For years, the advice was straightforward: use a VPN to protect your traffic. That advice remains valid — but it is incomplete. The security of the VPN gateway itself matters just as much as the encryption protecting the data flowing through it.

CISA's escalation from routine patching advisories to forensic triage mandates reflects the severity of this shift. Organizations cannot treat VPN gateways as set-and-forget appliances. They require the same continuous monitoring, rapid patching, and incident-response readiness as any other critical, internet-exposed system.

For individual users, the takeaway is more subtle but equally important: when choosing a VPN provider, the provider's infrastructure security practices — how quickly they patch, whether they run end-of-life software, how they handle disclosed vulnerabilities — are legitimate factors in your privacy decision. A VPN is only as secure as the weakest link in its chain, and in 2026, that weak link has increasingly been the gateway itself.

Known Exploited Vulnerabilities Catalog · Check Point VPN Flaws: Unauthenticated RCE Exploitation Imminent · Check Point VPN and Management Flaws Under Attack: Patch Two Different Trust Boundaries — Hive Security

A

Ali Ghanavati

Author at Valid VPN

More Reading

Related Articles

How Iran's Deep Packet Inspection Defeats Standard VPNs: Technical Reality and What Still Works
News

How Iran's Deep Packet Inspection Defeats Standard VPNs: Technical Reality and What Still Works

Iran's internet filtering infrastructure increasingly uses machine-learning-assisted deep packet inspection to identify and block commercial VPN protocols within seconds. This analysis explains how modern DPI detection works, why traditional VPN brands no longer offer reliable protection, and which obfuscation techniques remain viable—along with the genuine legal risks of VPN use in Iran.

Oct 10, 2026 Read More →

Ready to Bring Your Ideas to Life?

Let’s work together to create something useful, modern, and built for growth.

Get Your Free Quote
+13653879613 Get a Quote