# Hackers Target Security Gateway VPN with Critical RCE Vulnerability

*Published September 25, 2026*
*Source: [https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/](https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/hackers-target-security-gateway-vpn-with-critical-rce-vulnerability) or [see plans](https://www.sec-news.ai/pricing).*

## Article

A critical security flaw identified as CVE-2026-85102 in Check Point's Security Gateway VPN has become the target of active exploitation by hackers. This vulnerability resides in the VPN certificate functionality and allows for remote code execution before authentication. The exploitation of this flaw poses a significant threat to organizations using this technology, as attackers can potentially gain unauthorized access to sensitive data and systems.

Check Point has confirmed these attacks and is working to address the issue. The flaw allows attackers to execute arbitrary code on affected systems, which can lead to data breaches or disruptions in service. Organizations deploying Check Point's Security Gateway VPN should be on high alert and take immediate steps to mitigate the risk.

Security experts are urging affected organizations to apply any available patches or workarounds provided by Check Point. It is crucial to monitor systems for unusual activity that could indicate an attempted or successful exploit. Maintaining robust security practices and ensuring all systems are up-to-date can help reduce the risk of falling victim to these attacks.

In the face of increasing cyber threats, organizations must continue to prioritize cybersecurity measures. A proactive approach to vulnerability management and incident response can make a significant difference in protecting sensitive information and maintaining operational integrity.
