MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-23 · via BleepingComputer

Check Point confirms active attacks on VPN gateway vulnerability, adds second zero-day to advisory

Image via BleepingComputer
Image via BleepingComputer

Check Point has confirmed that attackers are actively exploiting a pre-authentication remote code execution flaw in the VPN certificate handling of its Security Gateway product. The company also disclosed a separate path traversal vulnerability in the Management web service that has been exploited as a zero-day since July. Both issues have been added to CISA's Known Exploited Vulnerabilities catalog, with federal agencies urged to patch by September 25.

Expanded Detail

The confirmed attacks began just two days after Dutch authorities warned that exploitation was imminent, suggesting threat actors moved quickly once details became public. Check Point observed attempts originating from anonymization services, with specific certificate subjects used in the intrusions, though the company cautioned that other identifiers may exist. The second flaw, a path traversal in the Management web service, has been exploited since late July, meaning attackers had a head start before the vendor’s advisory.

For administrators, the patch guidance is version-specific, requiring either LivePatch Take 26 or a fixed Jumbo Hotfix across multiple release lines. Those unable to update immediately can restrict VPN access by disabling implied rules and limiting peer IPs and ports. However, these mitigations do not apply to locally managed Spark firewalls, leaving some users with fewer options. CISA’s inclusion of both flaws in its KEV catalog sets a September 25 deadline for federal agencies.

Context

This active exploitation could disrupt organizations relying on Check Point VPNs for remote work, potentially exposing internal networks to unauthorized access or data theft. Because the flaws allow pre-authentication code execution, even unpatched systems behind firewalls may be at risk. Smaller businesses without dedicated security teams may struggle to apply urgent fixes, widening the gap between large enterprises and under-resourced entities. The rapid move from warning to confirmed attacks also highlights how quickly known vulnerabilities become weapons, pressuring all users to prioritize patching.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Check Point rushes hotfix for critical management server flaw under active exploitation · Cybersecurity
F5 issues emergency patch for BIG-IP APM zero-day under active exploitation · Cybersecurity
WordPress zero-day under active attack as exploit chain moves to file writes · Cybersecurity
US agency flags three actively exploited Linux kernel vulnerabilities, including a 14-year-old bug · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Check Point warns of hackers exploiting Security Gateway VPN RCE flaw.” Browse more stories.