Threat Brief — 2026-09-23 — Exploitation Escalates Across VPN and WordPress
Executive Summary
Two critical exploitation developments dominate today: Check Point has confirmed active in-the-wild exploitation of a pre-authentication RCE in its Security Gateway VPN product (CVE-2026-85102KEV), and threat actors have shifted from probing to actively weaponising WordPress CVE-2026-87902KEV to achieve code execution. Separately, researchers disclosed a new EDR evasion technique that poisons process initialisation structures to bypass endpoint detection, and Apple announced enhanced iOS protections that evaluate the context of transactions rather than just user identity to counter social engineering.
Top items
- Check Point Security Gateway VPN — pre-auth RCE actively exploited (CVE-2026-85102KEV, in CISA KEV). Check Point has confirmed attackers are exploiting a pre-authentication remote code execution vulnerability in the VPN certificate-handling functionality of Security Gateway. The CVE is listed in CISA's Known Exploited Vulnerabilities catalogue, meaning active exploitation is established. No workaround details are provided beyond vendor confirmation. This develops the broader KEV-tracking story first reported 2026-08-17 by CISA. (src: BleepingComputer)
- WordPress CVE-2026-87902KEV — attackers move from probing to active code execution. Threat actors have progressed beyond scanning and are now exploiting this WordPress vulnerability to write files to disk that execute shell commands when accessed. This is a significant escalation from the patch release first reported 2026-09-18; the flaw is now being actively weaponised rather than merely probed. (src: BleepingComputer)
- New EDR evasion technique — process parameter poisoning bypasses endpoint detection. Researchers detailed a method that injects code into process initialisation structures without invoking the Windows APIs that EDR products typically monitor. By manipulating process parameters at creation time, the technique sidesteps common userland hooking mechanisms. No specific threat actor or campaign is named; the findings are research-stage at this point. (src: Dark Reading)
- Apple strengthens iOS against social-engineering-driven transactions. Apple is shifting its fraud-detection model to assess the circumstances under which a financial or sensitive action is taken, rather than solely verifying the device owner's identity. The approach aims to block scammers who manipulate users into authorising transactions on legitimate interfaces. This is a defensive development, not an active exploit. (src: SecurityLab)
Themes
Exploitation maturation. Both the Check Point VPN and WordPress stories represent the same arc — vulnerabilities disclosed and patched (or KEV-listed) weeks ago are now seeing active weaponisation rather than reconnaissance. The window between advisory and real-world exploitation continues to compress.
Endpoint defence gaps. The EDR evasion research highlights that process-injection detection remains incomplete when attackers avoid the well-instrumented Windows API surface, reinforcing the need for kernel-level telemetry and behavioural baselines rather than API hooking alone.
