Opens in a new tab

Check Point confirms active exploitation of Security Gateway VPN flaw, ships fixes

  • Home
  • Blog
  • Check Point confirms active exploitation of Security Gateway VPN flaw, ships fixes
Check Point Security Gateway server exposed to glowing data breach streams

Check Point has confirmed that attackers are actively exploiting CVE-2026-85102, a pre-authentication remote code execution flaw in the VPN certificate handling functionality of its Security Gateway product. A second pre-authentication path traversal vulnerability, CVE-2026-93616, in the Management web service is also being exploited, and the Cybersecurity and Infrastructure Security Agency has added both flaws to its Known Exploited Vulnerabilities catalog.

What Check Point disclosed

The Security Gateway flaw sits in VPN certificate handling, allowing remote code execution before any user authentication. The Management web service flaw, CVE-2026-93616, is a path traversal issue that can lead to script execution and Java class loading. According to the advisory, CVE-2026-93616 has been exploited as a zero-day since July 23, and malicious activity against CVE-2026-85102 began on September 12.

On September 10, the Dutch Nationaal Cyber Security Centrum alerted on the Security Gateway issue and warned that imminent exploitation was expected. Two days later, exploitation attempts against Spark customers were observed, originating from anonymization infrastructure, including VPN services and proxies, to hide attacker location. Certificates with three observed subject strings were used in the campaign: CN=vpn,OU=users,O=global; CN=vpn-user,OU=users,O=global; and CN=vpnuser,OU=users,O=global. Check Point noted that the three subjects only reflect current observations and more may be in use.

Why this matters for defenders

Pre-authentication remote code execution on a network security appliance is the worst-case category of vulnerability, because it can be reached by any device on the management or VPN interface before any credentials are presented. Combined with active exploitation, the window between disclosure and patching is the period of highest risk, especially for organizations that expose management or VPN ports to the internet.

CISA has added both flaws to the Known Exploited Vulnerabilities catalog and instructed federal agencies to apply available fixes or mitigations by September 25, 2026.

Which fixes apply to your gateways

For CVE-2026-85102, the advisory recommends installing Check Point LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways, or installing a fixed Jumbo Hotfix: R81.20 Take 166, R82 Take 126, R82.10 Take 44, or R81.10 Take 190, or later. Spark firewalls should be updated to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later.

Administrators can verify whether LivePatch is active by running the cpinfo -y CPupdates command on the Security Gateway in expert mode. Check Point specifically warns that customers who installed an earlier offline LivePatch package need Take 26 for full coverage. The mitigation guidance does not apply to locally managed Spark firewalls.

Mitigations when patching is not possible

If updates cannot be applied right away, the advisory recommends disabling the VPN implied rules and creating explicit rules that restrict Site-to-Site VPN on UDP/500 and UDP/4500 to specific peer IP addresses. For Remote Access VPN, allow only the required services over UDP/500, UDP/4500, TCP/443, and TCP/80 where applicable, and restrict source client IP ranges where possible.

For hunting and mitigation guidance on the Management web service CVE-2026-93616, Check Point points administrators to its support article on that flaw.

What to do next

Treat any Security Gateway or Spark firewall exposed to the internet as a priority for patching this week. Confirm the build version, apply the listed Hotfix or LivePatch Take 26, and verify the patch is active with cpinfo. Audit VPN logs for certificate subjects matching the three observed strings, and check the Known Exploited Vulnerabilities catalog entry for the September 25 deadline that applies to federal agencies and the broader signal it sends to private sector defenders.

FAQ

What is CVE-2026-85102?

CVE-2026-85102 is a pre-authentication remote code execution vulnerability in the VPN certificate handling functionality of Check Point Security Gateway. Active exploitation began on September 12, 2026, and CISA has added it to the Known Exploited Vulnerabilities catalog.

What is CVE-2026-93616?

CVE-2026-93616 is a pre-authentication path traversal vulnerability in the Check Point Management web service that can allow script execution and Java class loading. It has been exploited as a zero-day since July 23, 2026.

How should administrators fix the Security Gateway flaw?

Install Check Point LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways, or install Jumbo Hotfix R81.20 Take 166, R82 Take 126, R82.10 Take 44, or R81.10 Take 190, or later. Spark firewalls should be updated to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later, and LivePatch status can be verified with cpinfo -y CPupdates.


This article summarizes reporting from bleepingcomputer.com.

← All Articles