Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
2026-09-13T13:23:22Z•0287f6f5fd3e204d1e61b2a41a99848b6cc8a865429d6797a9300445efc8bd46
CVE-2026-85102CVE-2026-85103CVE-2026-85706AI-abuseAndroid-malwareCheck-Point-VPNGitLabJFrog-ArtifactoryMicrosoft-365PaperCutVPNWindows-Serverauthentication-bypassbackdoorcredential-theftdata-breachpatch-managementpath-traversalphishingprivilege-escalationransomwarespywarevulnerability-exploitation
What happened
A BleepingComputer security-news digest reports imminent exploitation of critical Check Point VPN vulnerabilities (CVE-2026-85102 and CVE-2026-85103), active exploitation of JFrog Artifactory and PaperCut flaws, and a maximum-severity GitLab path-traversal flaw. It also covers phishing and credential theft targeting Microsoft 365, Trezor users, and Florida’s DMV database, malware campaigns including Android ransomware/spyware, AI-platform abuse, and security-update outages affecting Windows services. The most urgent risks are internet-facing VPN, Artifactory, GitLab, and PaperCut systems that,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 0287f6f5fd3e204d1e61b2a41a99848b6cc8a865429d6797a9300445efc8bd46
- Enrichment time
- 2026-09-13T13:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.