Today's threat landscape reads like a stress test for every tier of enterprise defense. In a single news cycle, defenders are contending with pre-authentication remote code execution in perimeter VPN gateways, a zero-day in OAuth-serving load balancers, a sophisticated browser exploit chain attributed to a Chinese state-linked actor, and a server-side code execution flaw hiding inside a popular web framework. Layered on top of all of this is a joint FBI-CISA advisory reminding critical infrastructure operators that their third-party ICS integrators represent a significant and often underestimated attack surface. The common thread is urgency: multiple of these vulnerabilities are confirmed as actively exploited in the wild right now.

The most immediately alarming item for network defenders is CVE-2026-85102, a pre-authentication RCE flaw in Check Point Security Gateway's VPN certificate-handling functionality. Pre-authentication vulnerabilities in perimeter devices are among the most dangerous class of bugs that exist — an attacker does not need credentials, a foothold, or any prior access to begin executing code on a device that sits at the edge of your network and holds the keys to your internal environment. Check Point has confirmed active exploitation. If your organization runs Security Gateway in a VPN configuration, this is a drop-everything patching event. Until the patch is applied, consider whether internet-facing VPN endpoints can be placed behind additional access controls or temporarily restricted by source IP.

Equally severe is CVE-2026-94127 in F5 BIG-IP Access Policy Manager. This zero-day affects deployments configured as OAuth authorization servers, meaning exploitation could allow an unauthenticated attacker to execute arbitrary code and potentially issue fraudulent OAuth tokens. The downstream consequences of token compromise extend well beyond the BIG-IP device itself — applications and APIs trusting those tokens could be silently accessed by attackers presenting forged credentials. F5 has released patches and organizations should treat this as a parallel priority to the Check Point issue. Audit which BIG-IP APM instances are configured in OAuth server mode and prioritize those for immediate remediation.

While network teams are racing to patch perimeter devices, endpoint and browser security teams face a separate crisis. The Chinese threat actor tracked as UTA0565 is actively chaining three zero-day vulnerabilities — CVE-2026-85046 and CVE-2026-87491 in Google Chrome, and CVE-2026-85880 in Windows — to deliver a malware family called CLEANGULP. The attack vector is browser-based, delivered through fake or compromised websites, meaning any user browsing the web on an unpatched system is a potential victim. CLEANGULP's capabilities have not been fully disclosed publicly, but the use of a multi-stage zero-day chain by a state-linked actor signals a high-value targeting campaign. Patch Chrome and Windows immediately, enforce browser isolation for high-risk user populations such as executives and finance teams, and review endpoint detection telemetry for unusual process spawning from browser processes.

For development and DevOps teams, CVE affecting Next.js ImageResponse deserves attention that it may not receive given the louder noise from the perimeter vulnerabilities. When attacker-controlled input such as URL parameters is passed into the ImageResponse SVG rendering pipeline without sanitization, server-side code execution becomes possible. This is a classic injection pattern in a modern framework context. Any application that exposes ImageResponse functionality to user-supplied input should be upgraded to the patched Next.js version immediately, and input validation should be enforced as a defense-in-depth measure regardless of patch status.

Finally, the joint FBI-CISA advisory on third-party ICS integrators is a timely reminder that the vulnerabilities above do not exist in isolation. Critical infrastructure operators frequently grant elevated network access to integrators for maintenance and support of industrial control systems. If those integrators are themselves compromised — or if their remote access pathways are not properly segmented and monitored — they become a trusted vector into environments where the consequences of intrusion extend beyond data loss into physical safety.

Defensive priorities for today:

- Apply Check Point Security Gateway patches for CVE-2026-85102 immediately; restrict VPN endpoint exposure as an interim measure
- Patch F5 BIG-IP APM for CVE-2026-94127 with priority on OAuth server-configured instances; audit issued tokens for anomalies
- Deploy Chrome and Windows updates to address the UTA0565 zero-day chain (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880); enable enhanced browser telemetry and hunt for CLEANGULP indicators
- Upgrade Next.js deployments and enforce strict input validation on any ImageResponse usage exposed to user input
- Review third-party ICS integrator access: enforce least-privilege, require MFA, segment integrator network paths, and log all remote sessions
- Escalate perimeter device patch status to leadership given the confirmed active exploitation across Check Point and F5 products

This briefing is informational and intended to support situational awareness — always consult official vendor advisories and your organization's patch management process for authoritative remediation guidance.