Check Point Patches Two 9.8-Rated Flaws Under Attack, One Since July 23
Security / news
Check Point Patches Two 9.8-Rated Flaws Under Attack, One Since July 23
Gateway bug CVE-2026-85102 was exploited three days after its fix; the management bug CVE-2026-93616 had no fix for 61 days.

An unauthenticated remote attacker can run code on a Check Point Security Gateway or Spark Firewall by sending a crafted certificate during VPN negotiation (the exposed device has to be one that negotiates VPN). Check Point said exploitation of that flaw, CVE-2026-85102, began on September 12, three days after its fix shipped.
The vendor's advisory covers a second bug, CVE-2026-93616, in the Security Management web service. It was exploited in limited, targeted attacks from July 23, and its fix arrived only with the advisory on September 22. Both are rated 9.8 on the CVSS scale.
Install the fixes first. Then review VPN logs for the certificate subjects listed below.

Timeline: July 23 to September 25
| Date (2026) | Event |
|---|---|
| July 23 | Earliest attacks Check Point observed against CVE-2026-93616 |
| September 9 | CVE-2026-85102 disclosed and fixed |
| September 10 | The Dutch NCSC warned that exploitation of the VPN flaw was imminent, BleepingComputer reported |
| September 12 | Exploitation wave against Spark customers begins |
| September 22 | CISA adds both CVEs to its Known Exploited Vulnerabilities catalog; fix for CVE-2026-93616 ships |
| September 25 | Deadline for U.S. federal civilian agencies to remediate |
The ordering matters more than the score. Anyone who patched the gateway bug on September 9 was ahead of the attacks by three days. Anyone running Security Management had no fix for a bug that had been under attack for 61 days.
- CVE-2026-93616 (Management)61 days
- CVE-2026-85102 (Gateway VPN)10 days
Source: Dates from Check Point advisory and CISA alert, accessed 2026-09-28; day counts calculated by The Terminal
What CVE-2026-85102 needs
Check Point describes the flaw as "improper validation of certificate data during VPN negotiation" that allows unauthenticated remote code execution. Affected releases are R81, R81.10.X, R81.20, R82, R82.00.X and R82.10, on Security Gateway and on centrally and locally managed Spark Firewalls.
The interim controls in the advisory are all VPN restrictions. Check Point advises disabling VPN implied rules, limiting Site-to-Site VPN to named peer addresses on UDP 500 and UDP 4500, and adding source restrictions to Remote Access VPN where possible.
The fix is LivePatch Take 26 for R81.20, R82 and R82.10. Spark firewalls need R82.00.10 Build 2325 or R81.10.17 Build 4968 and later.
The attempts Check Point saw used certificates whose subjects resembled "CN=vpn,OU=users,O=global", and it said more variations may be in use. They came from anonymisation infrastructure, including VPN services and proxies. That makes the source address useless as an indicator. The certificate subject and any anomalous certificate-based Mobile Access login are the better ones, along with port scans or service scans from a user who has just logged in.
What CVE-2026-93616 needs
This one sits on the management server rather than the edge. The advisory calls it a pre-authentication path traversal in the management web service that leads to arbitrary-path script execution and a Java class load.
| Release | Vulnerable at or below |
|---|---|
| R82.20 | listed with no hotfix threshold |
| R82.10 | Jumbo Hotfix Take 44 |
| R82 | Jumbo Hotfix Take 126 |
| R81.20 | Jumbo Hotfix Take 166 |
| R81.10 | Jumbo Hotfix Take 190 |
| R80 | all versions |
Check Point points to support article sk1000171 for the fix and for compromise indicators. The advisory describes the attacks as limited and targeted, with no count of victims. Check Point did not say who was behind them, and CISA's alert does not say either.
Security consultancy Truesec also published guidance repeating Check Point's affected versions. It adds no independent exploitation data.
For other recent patching stories on this site, see the Siemens Keycloak password-reset flaw and the malicious Terraform provider.
The federal deadline of September 25 has passed. Check Point has not said whether it expects further variations of the malicious certificate subjects.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.