Cybersecurity company Check Point has confirmed active exploitation of CVE-2026–85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product.
The same advisory also warns of threat actors exploiting a pre-authentication path traversal flaw tracked as CVE-2026–93616, which impacts the Management web service and can allow script execution and Java class loading.
The company says that CVE-2026–93616 has been exploited as a zero-day since July 23.
