Your VPN gateway might already be compromised. Check Point, one of the world’s most widely deployed security appliance vendors, just confirmed that threat actors are actively exploiting a critical pre-authentication remote code execution vulnerability in its Security Gateway product right now—not in theoretical scenarios, but in real-world attacks against customer networks.
The vulnerability, tracked as CVE-2026-85102, resides in how the Security Gateway handles VPN certificate validation. Because it exists before authentication occurs, attackers don’t need valid credentials to trigger it. They simply need network access to the VPN endpoint. For many organizations, that’s the entire internet.
Why This Matters More Than Typical Vulnerabilities
Remote code execution flaws in security appliances occupy a special tier of severity. Unlike vulnerabilities in client applications that require user interaction or specific conditions, RCE in a gateway product gives attackers direct access to your perimeter defense infrastructure itself. Once compromised, an attacker doesn’t just breach your VPN—they control the system that’s supposed to protect your entire network from the internet.
The pre-authentication aspect elevates this further. Traditional VPN vulnerabilities often require some form of authentication or knowledge of valid credentials. This one doesn’t. Any attacker on the internet with the ability to reach your Security Gateway can attempt exploitation. Given that VPN appliances are necessarily exposed to the internet by design, the practical attack surface is enormous. This is exactly the type of flaw that gets targeted by sophisticated threat actors immediately upon disclosure.
Active Exploitation Confirmed
Check Point’s confirmation that hackers are already weaponizing CVE-2026-85102 means this isn’t a theoretical risk anymore. Security teams worldwide have shifted from prevention mode to incident response mode. For organizations running vulnerable versions of Security Gateway without patches deployed, the question isn’t whether you’ve been targeted—it’s whether you’ve been successfully compromised.
The active exploitation phase creates urgency that supersedes normal change management windows. Waiting for your quarterly patch cycle isn’t an option here. Many cybersecurity professionals recommend treating this like you’d treat a ransomware outbreak: immediate patching, emergency maintenance windows, and accelerated deployment schedules regardless of typical testing protocols.
Organizations should assume threat actors have developed reliable exploitation code by now. The discovery-to-weaponization timeline for flaws of this caliber typically measures in hours or days, not weeks. If your Security Gateway hasn’t been updated, your infrastructure may already be sitting in an attacker’s staging area.
Response and Remediation Steps
Check Point has released security patches addressing the vulnerability. However, knowing a patch exists and deploying it across your infrastructure are different challenges entirely. In distributed organizations with multiple geographic locations or complex network topologies, patching every affected Security Gateway quickly requires coordination and planning.
Your immediate action items should include: identifying all Security Gateway instances in your environment and their current firmware versions, prioritizing patches for internet-facing deployments, establishing a maintenance window that minimizes business disruption, and monitoring logs for signs of exploitation attempts. Some organizations find value in temporarily restricting VPN access to essential users only during the patching window, reducing the window of exposure.
Beyond the security patch itself, security teams should review firewall logs and VPN access logs for any suspicious certificate-related errors or unexpected traffic patterns from unusual source IPs. While active exploitation is happening, forensic evidence may still be recoverable on your systems.
Key takeaway: A pre-authentication RCE in your VPN gateway is about as serious as cybersecurity threats get. The data breach potential here isn’t limited to user credentials or files—it extends to complete network compromise. Check Point’s confirmation of active attacks means every moment your Security Gateway remains unpatched increases your organizational risk. This isn’t a vulnerability to schedule; it’s one to treat as a security incident waiting to happen.
If you’re running Check Point Security Gateway, have you already deployed the patch, or is this the first you’re hearing about the active exploitation campaign?
Get Tech Savvy Digest in your inbox
IT news, cybersecurity, and crypto — the signal, not the noise. No spam, unsubscribe anytime.

