Act
active
Check Point Security Gateway VPN pre-auth RCE exploited in the wild
- Engineer — Act: Pre-auth RCE on a widely deployed VPN gateway with CISA KEV listing, active exploitation, and a public PoC demands immediate action: apply Check Point’s patch for CVE-2026-85102, then audit gateway logs for signs of pre-patch compromise.
- SOC/IR — Act: Active exploitation of an edge VPN device requires an assume-breach posture: hunt for unusual outbound connections or lateral movement originating from or through Check Point Security Gateway hosts since the earliest known exploitation date, and check threat intel feeds for published IOCs tied to this campaign.
- Leader — Act: CISA KEV listing and confirmed active exploitation of a perimeter VPN appliance are board-question-level conditions: confirm whether Check Point Security Gateway is in your environment, verify your team has an emergency patch plan, and be ready to brief leadership on exposure before this surfaces in the news.
- Signals: CVE-2026-85102 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.