1. Home
  2. Security Advisories

Check Point Vulnerability: CVE-2026-85102 Actively Exploited

Security advisory Critical 5 min read

This article is also available in: TürkçeDeutsch

Check Point Vulnerability: CVE-2026-85102 Actively Exploited
CVECVE-2026-85102, CVE-2026-93616, CVE-2026-85103
SeverityCritical
CVSS score 9.8
StatusPatch available
Affected productsCheck Point Security Gateway R81.20, R82, R82.10; Spark R81.10.x, R82.00.x; Security Management/MDS/Log Server/SmartEvent R81.10 – R82.20 (Jumbo Takes before the fix); end-of-support R80 – R81.10

Check Point confirms active exploitation of CVE-2026-85102 and CVE-2026-93616 (CVSS 9.8), affecting VPN gateways and management servers. Affected versions and patching steps.

Summary

On 22 September 2026, Check Point announced that two critical Check Point vulnerabilities affecting its security gateways and management servers are being actively exploited. Both carry a CVSS score of 9.8 and require no authentication: one enables remote code execution on the VPN gateway, the other opens the door to compromising the server that manages all security policies. A flaw like this on the devices guarding your network perimeter is an immediate top priority.

  • CVE-2026-85102 (CVSS 9.8): Unauthenticated remote code execution in Security Gateway and Spark Firewall due to a flaw in VPN certificate validation. Patches have been available since 9 September; attacks started on 12 September.
  • CVE-2026-93616 (CVSS 9.8): Pre-authentication path traversal in the management server web service. A zero-day used in a small number of targeted attacks since 23 July; the fix was released on 22 September.
  • CISA KEV: Both flaws were added to the catalog on 22 September 2026; the deadline for US federal agencies was 25 September.

Check Point vulnerability: technical details

Check Point disclosed and fixed CVE-2026-85102 on 9 September 2026, when there was no evidence of exploitation. The Dutch National Cyber Security Centre (NCSC) had also warned that exploitation was imminent. According to Check Point's new advisory, a global wave of exploitation targeting Spark customers began on 12 September. The attacks originate from VPN services and anonymization infrastructure such as proxies, and use certificates with the following subjects:

  • CN=vpn,OU=users,O=global
  • CN=vpn-user,OU=users,O=global
  • CN=vpnuser,OU=users,O=global

The vendor stresses that this list is not exhaustive and that other subjects may be used.

CVE-2026-93616, announced in the same advisory, is a path traversal flaw in the management web service. It allows an attacker to execute a script from an arbitrary location and load an arbitrary Java class. Check Point says a small number of customers were targeted through this flaw.

The updates released on 9 September also fix CVE-2026-85103, a heap overflow in the ASN.1 parsing of VPN certificates. No active exploitation has been reported for this flaw, and since it is fixed by the same patch, no separate action is needed.

Affected versions

ProductAffectedFixed
Security Gateway (CVE-2026-85102, with VPN)R81.20, R82, R82.10LivePatch Take 26 or Jumbo Hotfix R81.20 Take 166, R82 Take 126, R82.10 Take 44 and later
Spark Firewall (centrally / locally managed)R81.10.x, R82.00.xR81.10.17 Build 4968, R82.00.10 Build 2325 and later
Security Gateway – end of supportR80 – R81.10R81.10 Jumbo Take 190 (EoS) / upgrade to a supported version
Security Management, MDS, Log Server, SmartEvent (CVE-2026-93616)R82.20; R82.10 Take 44 and below; R82 Take 126 and below; R81.20 Take 166 and below; R81.10 Take 190 and belowR82.20 Security Hotfix; Jumbo R82.10 Take 45, R82 Take 127, R81.20 Take 170, R81.10 Take 192 and later
Management server – end of supportR80 – R81Upgrade to a supported version

According to Check Point, Smart-1 Cloud (fix already applied), Check Point firewall appliances and Spark Firewall are not affected by CVE-2026-93616. R82.20 is not listed among the versions affected by CVE-2026-85102.

Risk and potential impact

An attacker who compromises the gateway gains a foothold right at the entrance to the corporate network. Check Point reports that successful logins are typically followed by port and service scanning of the internal network. Compromising the management server can be even more serious: it holds the policies, configurations and credentials of all gateways, so a single server can be used to change the entire firewall estate.

Organizations using Remote Access VPN for remote work are particularly exposed. By design, the service must be reachable from the internet, so restricting source IP addresses is not always possible.

  1. Patch gateways for CVE-2026-85102: Apply Check Point LivePatch Take 26 on R81.20, R82 and R82.10. If you previously installed an offline LivePatch package, you need to move to Take 26 for full protection. You can check the LivePatch status in Expert mode with cpinfo -y CPupdates. Alternatively, install Jumbo Hotfix R81.20 Take 166, R82 Take 126, R82.10 Take 44 or R81.10 Take 190 or later.
  2. Update Spark appliances: Move to R82.00.10 Build 2325 or R81.10.17 Build 4968 or later.
  3. Patch management servers for CVE-2026-93616: Install the R82.20 Security Hotfix or Jumbo Hotfix R82.10 Take 45, R82 Take 127, R81.20 Take 170 or R81.10 Take 192 or later. LivePatch does not address this flaw.
  4. Restrict management access: Make sure TCP/19009 is reachable only from trusted IP addresses and limit the "Trusted Clients" list in SmartConsole to trusted internal addresses.
  5. Hunt for signs of compromise: Review the logs for unusual certificate-based Mobile Access logins and do not limit your search to the certificate subjects above. On management servers, run the IoC check commands from sk1000171.
  6. If you cannot patch immediately: Disable the implied VPN rules and create explicit rules that open UDP/500 and UDP/4500 for Site-to-Site VPN only to known peer IP addresses. For Remote Access VPN, allow only the required services and restrict source IP ranges where possible. These measures cannot be applied on locally managed Spark appliances and do not replace patching.
  7. Move off unsupported versions: If you are running end-of-support versions such as R80–R81.10, plan an upgrade to a supported release.

How Doğa Network can help

Our team can support you with version audits of your Check Point gateways and management servers, Jumbo Hotfix/LivePatch planning, access restrictions and log reviews. Call us on +90 850 888 3642 or email hi@doga.network.

Sources

#Check Point#firewall#VPN#Spark#CVE-2026-85102#CVE-2026-93616
Newsletter

Hear about critical vulnerabilities first.

Get our security advisories, practical guides and announcements by email. A few emails a month, no advertising.

Which topics would you like to hear about?