Skip to finding
important · RCE — VPN

Check Point says attackers are exploiting its pre-authentication VPN certificate RCE against Spark gateways.

Affects

Check Point Security Gateway and Spark Firewall, embedded network-security appliances providing firewall and VPN services.

Malicious certificate data supplied during VPN negotiation can execute code before authentication in the gateway service context.

Detail and 1 source
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 25, 2026