Follow the latest coverage, related explainers and connected technology stories.
Check Point confirmed that two vulnerabilities in Security Gateway are being actively exploited, one enabling remote command execution before authentication, while the other has been exploited as a zero-day since July 23, 2026. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog, giving U.S. federal agencies until September 25 to apply fixes or mitigation measures.