تحذير .. شركة أمن سيبراني تكتشف ثغرة حرجة فى بوابات VPN

23 سبتمبر 2026·اليوم السابع
تحذير .. شركة أمن سيبراني تكتشف ثغرة حرجة فى بوابات VPN

أطلقت شركة الأمن السيبراني العالمية Check Point تحذيرًا أمنيًا عاجلاً لكافة المؤسسات والشركات بعد رصد استغلال نشط في الفضاء الرقمي لثغرة أمنية حرجة تحمل الرمز CVE-2026-85102، وتصيب هذه الفجوة الخطيرة بوابات الأمان والاتصال الافتراضي الخاص Security Gateway VPN، وتتيح للمهاجمين تنفيذ تعليمات برمجية عن بعد بصلاحيات إدارية كاملة قبل مرحلة المصادقة Pre-Authentication، مما يضع أنظمة الاتصال المشفرة وشبكات الشركات تحت خطر الاختراق المباشر والتسلل لقواعد البيانات الداخلية دون الحاجة لبيانات اعتماد مسبقة.

شهادات الأمان الرقمية وثغرات إدارة الخوادم تتطلب معالجة فورية

وفقًا لنشرة أمنية رسمية منشورة بمدونة Check Point الأمنية، يمثل هذا التهديد خطرًا داهمًا على استمرارية الأعمال وسرية الاتصالات المؤسسية، حيث يستغل المتسللون خللاً في بروتوكول فحص شهادات الأمان الرقمية لتمرير حزم بيانات خبيثة تعطل آليات الفحص وتفتح أبوابًا خلفية داخل جدران الحماية، وأوضح التقرير الفني أن الشركة رصدت أيضًا ثغرة مرافقة تحمل الرمز CVE-2026-93616 في خوادم الإدارة، داعية مديري الشبكات في كافة القطاعات الحيوية إلى تطبيق الإصلاحات البرمجية الفورية الصادرة، وعزل بوابات VPN عن محاولات الوصول المريبة، وفحص سجلات الدخول للتأكد من عدم وجود أي أنشطة تجسس رقمية غير مصرح بها.

تعزيز المرونة السيبرانية لحماية بيئات العمل

تشدد التوجيهات الوقائية على ضرورة تفعيل آليات المصادقة المزدوجة وتحديث جدران الحماية بصفة مستمرة، وسوف تسهم هذه الإجراءات الصارمة في سد مسارات الهجوم وتحصين أصول الشركات والمعاملات الرقمية ضد القرصنة المتقدمة.



Check PointVPNsecurity
الخبر متوفّر باللغات التالية:English
المصدر الأصلي للخبر
اليوم السابع

Warning: Cybersecurity Company Discovers Critical Flaw in VPN Gateways

September 23, 2026·Youm7
Warning: Cybersecurity Company Discovers Critical Flaw in VPN Gateways

Global cybersecurity company Check Point has issued an urgent security alert to all institutions and companies after detecting active exploitation in the digital space of a critical vulnerability with the CVE-2026-85102 code, which affects the Security Gateway VPN security and virtual communication gateways. This serious gap allows attackers to execute remote code with full administrative privileges before authentication, putting encrypted communication systems and corporate networks at risk of direct penetration and infiltration of internal databases without the need for prior credentials.

Digital security certificates and server management vulnerabilities require immediate attention

According to an official security bulletin published on the Check Point Security blog, this threat poses an imminent danger to business continuity and the confidentiality of institutional communications. Hackers exploit a flaw in the protocol for examining digital security certificates to pass malicious data packets that disable scanning mechanisms and open backdoors within firewalls. The technical report also clarifies that the company has also detected a related vulnerability with the CVE-2026-93616 code on management servers, calling on network administrators across all vital sectors to apply immediate software patches issued, isolate VPN gateways from suspicious access attempts, and examine login logs to ensure there is no unauthorized digital espionage activity.

Boosting Cybersecurity Resilience to Protect Work Environments

Preventive guidelines emphasize the need to activate dual authentication mechanisms and continuously update firewalls. These stringent measures will help block attack pathways and fortify corporate assets and digital transactions against advanced hacking.



Check PointVPNsecurity
This article is also available in:العربية
Original source article
Youm7