started · updated
Check Point and Citrix issue patches for critical security vulnerabilities
Cybersecurity firms and national agencies have issued warnings regarding critical vulnerabilities affecting major network security products.
Check Point has announced patches for two critical-severity vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which carry a CVSS score of 9.8. These defects could allow for unauthenticated remote code execution (RCE) in gateway and firewall products using VPN functionality. The vulnerabilities involve improper certificate data validation and heap overflows. While Check Point discovered these internally and found no evidence of active exploitation, the company recommends manual VPN rule definitions or applying the latest Jumbo hotfixes as mitigations.
Separately, threat actors are actively exploiting a combination of vulnerabilities in Citrix NetScaler ADC and Gateway deployments. This attack chain utilizes CVE-2026-19490, an authentication bypass flaw, alongside CVE-2026-8452, a critical RCE vulnerability. Exploitation allows for unauthorized administrative access and lateral movement within enterprise networks. Agencies such as CISA and CSA Singapore have issued urgent advisories following a surge in attacks linked to public proof-of-concept code.