Organizations running Check Point Security Gateway VPN appliances must take immediate action. The vendor has confirmed that a critical remote code execution vulnerability in its products is under active, widespread attack by threat actors.
Check Point has verified that the flaw, tracked as CVE-2026-85102, is being exploited in the wild. The vulnerability exists within the VPN certificate-handling functionality of the Security Gateway. With a CVSS score of 9.8, it is particularly severe due to its pre-authentication nature, allowing attackers to execute arbitrary code without any valid user credentials.
The flaw's location within the VPN gateway presents a prime target. A successful attack grants a threat actor a direct foothold inside the corporate network from the internet, completely bypassing perimeter defenses. This provides a clear path for data theft and further network compromise. The confirmation of active exploitation shifts the risk from theoretical to a verified, immediate operational threat.
The mandate for IT and security teams, especially in high-risk regions like Hong Kong, is to patch immediately. The primary directive is to deploy the official security updates released by Check Point without delay. Priority must be given to all internet-facing Security Gateway appliances with VPN services enabled. Organizations should first verify their appliance model and software version against the vendor advisory to confirm exposure.
For environments where immediate patching is not feasible, critical interim mitigations must be implemented at once. The most essential step is to restrict VPN access at the network layer, allowing connections only from trusted, pre-defined IP addresses. Concurrently, teams must enhance monitoring and logging on all Security Gateway appliances to actively search for indicators of anomalous activity or exploitation attempts.
This incident highlights the critical vulnerabilities that can lurk within perimeter security infrastructure. Organizations relying on Check Point's VPN solutions must treat this as a top priority. The window for proactive defense has closed; the focus must now be on active threat hunting using vendor-published IOCs and definitive patching to secure networks.
所有使用 Check Point Security Gateway VPN 設備的機構必須立即採取行動。供應商已確認,其產品中存在一個嚴重的遠端代碼執行漏洞,目前正遭受威脅行為者積極且廣泛的攻擊。
Check Point 已核實編號為 CVE-2026-85102 的漏洞正在野外被利用。該漏洞存在於 Security Gateway 的 VPN 證書處理功能中。其 CVSS 評分為 9.8,由於其屬於預認證漏洞,攻擊者無需任何有效用戶憑證即可執行任意代碼,因而特別嚴重。
該漏洞位於 VPN 閾道內,成為絕佳攻擊目標。一次成功的攻擊能讓威脅行為者直接從互聯網立足於企業網絡內部,完全繞過周邊防禦體系。這為數據竊取及進一步的網絡入侵提供了明確路徑。證實漏洞正被主動利用,將風險從理論層面轉變為已證實的、即時的運營威脅。
對 IT 和安全團隊,特別是位於香港等高風險地區的團隊而言,其首要任務是立即進行修補。首要指令是毫不延遲地部署 Check Point 發布的官方安全更新。所有啟用 VPN 服務、面向互聯網的 Security Gateway 設備必須優先處理。各機構應首先根據供應商的公告核對其設備型號和軟件版本,以確認是否受到影響。
對於無法立即進行修補的環境,必須即刻實施關鍵的臨時緩解措施。最重要的一步是在網絡層面限制 VPN 訪問,僅允許來自可信、預定義 IP 地址的連接。同時,團隊必須加強對所有 Security Gateway 設備的監控和日誌記錄,主動搜索異常活動或利用嘗試的指標。
此次事件突顯了可能潛伏在周邊安全基礎設施內的嚴重漏洞。依賴 Check Point VPN 解決方案的機構必須將此視為最高優先級事項。主動防禦的窗口已經關閉;現在的重點必須是利用供應商發佈的 IOC 進行積極的威脅搜尋,並通過決定性的修補措施來確保網絡安全。
