Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

2026-09-13T13:23:22Z•0287f6f5fd3e204d1e61b2a41a99848b6cc8a865429d6797a9300445efc8bd46
CVE-2026-85102CVE-2026-85103CVE-2026-85706AI-abuseAndroid-malwareCheck-Point-VPNGitLabJFrog-ArtifactoryMicrosoft-365PaperCutVPNWindows-Serverauthentication-bypassbackdoorcredential-theftdata-breachpatch-managementpath-traversalphishingprivilege-escalationransomwarespywarevulnerability-exploitation

What happened

A BleepingComputer security-news digest reports imminent exploitation of critical Check Point VPN vulnerabilities (CVE-2026-85102 and CVE-2026-85103), active exploitation of JFrog Artifactory and PaperCut flaws, and a maximum-severity GitLab path-traversal flaw. It also covers phishing and credential theft targeting Microsoft 365, Trezor users, and Florida’s DMV database, malware campaigns including Android ransomware/spyware, AI-platform abuse, and security-update outages affecting Windows services. The most urgent risks are internet-facing VPN, Artifactory, GitLab, and PaperCut systems that,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
0287f6f5fd3e204d1e61b2a41a99848b6cc8a865429d6797a9300445efc8bd46
Enrichment time
2026-09-13T13:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.