Actively Exploited Zero-Days: Check Point, WordPress, Chrome, and PeopleSoft — K-12 and Government Response

Actively exploited zero-days in Check Point, WordPress, Chrome/Windows, and Oracle PeopleSoft. K-12 and government patch and mitigation guidance.

  • CISA added Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog, including Check Point CVE-2026-85102.
  • Check Point confirmed active exploitation of CVE-2026-85102 (Security Gateway VPN pre-auth RCE) and CVE-2026-93616 (Management Server unauthenticated script execution); WordPress, Chrome/Windows, and Oracle PeopleSoft zero-days are also in play.
  • K-12 and government teams should patch internet-facing VPNs, management servers, WordPress sites, browsers, and PeopleSoft, then hunt for compromise and rotate credentials.

What to do now

  1. Patch now: apply Check Point fixes for CVE-2026-85102 and CVE-2026-93616, update WordPress to 7.1.2 or later (CVE-2026-87902 and CVE-2026-93485), apply Chrome/Windows updates for CVE-2026-85046, CVE-2026-87491, CVE-2026-85880, and obtain Oracle PeopleSoft emergency guidance.
  2. If patching is delayed, remove internet exposure from VPN, management, and WordPress admin interfaces; disable certificate-based VPN auth where possible; require VPN or jump host and MFA for administration.
  3. Hunt logs from July 23 onward for Check Point unauthenticated script execution and VPN anomalies; review WordPress comments, file inclusion attempts, new admin accounts, and webshells; check Chrome/ALPC and fake-site visits from Sept 3-4.
  4. Isolate suspected systems, rotate VPN certificates, API keys, admin passwords, and WordPress salts; segment PeopleSoft and management servers from general networks.
  5. Subscribe to CISA KEV and vendor advisories; share indicators with the New Brunswick Department of Education and Canadian cyber authorities; conduct compromise assessments before restoring service.

Related items