Hi CheckMates,
I would like to compare notes with the community regarding the recently disclosed VPN vulnerabilities, specifically CVE-2026-85102 / sk1000117.
On September 14 we observed very similar suspicious activity on two separate Check Point gateways in two completely independent customer environments.
Before the gateways were updated, the logs show:
- Successful Remote Access VPN login events
- Authentication method shown as Certificate
- Certificate CNs such as vpnuser / vpn-user
- A 172.16.10.x Remote Access VPN IP being assigned
- Immediately afterwards, large numbers of VPN Decrypt connections towards internal networks
- Systematic scanning of internal IP ranges, mainly on TCP/389 (LDAP) and TCP/636 (LDAPS)
- In both environments the scanning pattern was highly automated
- At one point, very similar scanning activity occurred on both unrelated gateways almost simultaneously
We do not recognize these VPN sessions or certificates as legitimate user activity.
After installing the fix referenced in sk1000117, we have not observed any further successful sessions of this type.
We opened a TAC case and had a remote session with Check Point Support. TAC confirmed that the gateway is protected once the fix is installed. However, my concern is specifically about post-compromise remediation for activity that occurred before the fix was installed.
I therefore have a few questions for the community and, if possible, Check Point:
- Has anyone else seen successful certificate-based Remote Access VPN sessions followed by LDAP/LDAPS scanning in relation to these vulnerabilities?
- Is this logging pattern consistent with exploitation of CVE-2026-85102, or could there be another explanation?
- If unauthorized VPN access occurred before patching, is installing the fix considered sufficient remediation, or should the gateway be rebuilt/re-imaged?
- Are there specific Gaia / VPN / system logs or IOCs that should be checked to determine whether code execution or persistence occurred on the gateway itself?
- Should local gateway credentials, certificates or other secrets be rotated in this scenario?
I have preserved the gateway logs and can provide sanitized/anonymized log samples and timestamps if useful.
I am deliberately not posting customer names, public IP addresses or internal addressing at this stage.
Thanks in advance for any insight.