Threats

Check Point confirms active exploitation of CVE-2026-85102 and CVE-2026-93616 in Security Gateway VPN and Management services

September 23, 2026 20:00 · 6 min read
Check Point confirms active exploitation of CVE-2026-85102 and CVE-2026-93616 in Security Gateway VPN and Management services

Check Point confirms active exploitation of two critical Security Gateway vulnerabilities

Cybersecurity firm Check Point has confirmed that threat actors are actively exploiting two pre-authentication vulnerabilities in its Security Gateway products, including a remote code execution flaw and a path traversal issue impacting the Management web service. The vulnerabilities, tracked as CVE-2026-85102 and CVE-2026-93616, were disclosed in an advisory released on September 23, 2026, following warnings from the Dutch National Cyber Security Centre (NCSC) on September 10, 2026.

Details on CVE-2026-85102: VPN certificate-handling RCE flaw

CVE-2026-85102 is a pre-authentication remote code execution vulnerability located in the VPN certificate-handling functionality of Check Point Security Gateway devices. Exploitation of this flaw allows attackers to execute arbitrary code without authentication. Check Point observed exploitation attempts beginning on September 12, 2026, with attackers using VPNs and proxies to conceal their origin. The malicious activity specifically targeted Spark customers, with attack traffic originating from anonymization infrastructure.

The company noted that attackers used certificates with the following subject lines during observed exploitation: CN=vpn,OU=users,O=global; CN=vpn-user,OU=users,O=global; and CN=vpnuser,OU=users,O=global. Check Point emphasized that these subjects reflect only current observations and additional variants may be in use.

Details on CVE-2026-93616: Pre-authentication path traversal in Management web service

The second vulnerability, CVE-2026-93616, is a pre-authentication path traversal flaw affecting the Management web service of Security Gateway systems. This flaw enables attackers to execute scripts and load arbitrary Java classes, potentially leading to full system compromise. Check Point confirmed that this vulnerability has been exploited as a zero-day since July 23, 2026, making it actively used in the wild for over two months before public disclosure.

Mitigation and remediation guidance

To address CVE-2026-85102, Check Point recommends administrators install Check Point LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways. Alternatively, fixed Jumbo Hotfixes are available: R81.20 Take 166, R82 Take 126, R82.10 Take 44, or R81.10 Take 190, or later versions. Spark firewalls should be updated to R82.00.10 Build 2325 or R81.10.17 Build 4968, or newer.

Administrators can verify LivePatch activation by running the command cpinfo -y CPupdates in expert mode on the Security Gateway. Check Point warns that customers who previously installed an offline LivePatch package must apply Take 26 for complete protection.

If patching is not immediately possible, Check Point advises disabling VPN implied rules and creating explicit rules to restrict Site-to-Site VPN traffic on UDP/500 and UDP/4500 to specific peer IP addresses. For Remote Access VPN, only required services should be allowed over UDP/500, UDP/4500, TCP/443, and TCP/80, with source client IP ranges restricted where feasible. These mitigations do not apply to locally managed Spark firewalls.

CISA adds flaws to KEV catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added both CVE-2026-85102 and CVE-2026-93616 to its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies are urged to apply available fixes or mitigations by September 25, 2026, to reduce the risk of compromise.

For guidance on mitigating and hunting threats related to CVE-2026-93616 in the Management web service, Check Point directs customers to its official support article. Organizations are encouraged to review their exposure and apply patches promptly to prevent further exploitation.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free