Check Point has warned customers about the active exploitation of two critical vulnerabilities in its VPN gateway and Security Management products: CVE-2026-85102 and the newly disclosed CVE-2026-93616.
Both vulnerabilities have a CVSS score of 9.8 and allow for pre-authentication attacks, making immediate patching and reducing exposure essential.
CVE-2026-85102 is an improper certificate-validation vulnerability affecting Check Point Security Gateway and Spark Firewall VPN deployments. This flaw allows an unauthenticated remote attacker to execute arbitrary code during VPN negotiation, including in Remote Access and certificate-enabled Site-to-Site VPN configurations.
Check Point released a fix on September 9; however, they subsequently identified exploitation attempts against Spark Firewalls starting September 12.
The attacks reportedly originated from anonymization infrastructure, including VPN services and proxy networks. Check Point observed malicious certificates with subject names such as CN=vpn, OU=users, O=global, CN=vpn-user, OU=users, O=global, and CN=vpnuser, OU=users, O=global.
The vendor emphasizes that these indicators are not exhaustive, and defenders should investigate any anomalous certificate-based Mobile Access logins, regardless of the certificate subject.
Affected VPN products include Security Gateway and centrally or locally managed Spark Firewall devices running versions R81 through R82.10, including several end-of-support releases.
Version R82.20 is not affected by CVE-2026-85102. The fix is available through Check Point LivePatch Take 26, specific Jumbo Hotfix Accumulators, and updated Spark Firewall builds.
The second flaw, CVE-2026-93616, is a pre-authentication directory traversal and file upload vulnerability in Check Point Management web services.
This vulnerability enables an unauthenticated attacker to upload and execute arbitrary scripts on a compromised Management Server. Check Point has reported observing a limited number of targeted attacks in the wild.
This issue affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent installations. However, Smart-1 Cloud, Check Point Firewall Appliances, and Spark Firewalls are not affected by this vulnerability.
Affected versions include R82.20, R82.10 with Jumbo Hotfix Take 44 or earlier, R82 with Take 126 or earlier, R81.20 with Take 166 or earlier, and older end-of-support releases.
Unlike the VPN vulnerability, LivePatch Take 28/29 does not remediate CVE-2026-93616, as Check Point stated that a LivePatch is unavailable due to the nature of the fix.
Organizations should prioritize the following actions:
These two vulnerabilities underscore the heightened risk posed by internet-exposed VPN and management infrastructure. Organizations that have delayed patching should treat both issues as incident-response priorities, especially when remote-access services or centralized security-management servers are accessible from the outside.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…