Hackers are actively exploiting significant vulnerabilities in Check Point’s VPN and management products, posing a risk of unauthorized remote access and potential remote code execution. These vulnerabilities, identified as CVE-2026-85102 and CVE-2026-93616, have been assigned a critical CVSS severity score of 9.8, prompting Check Point to release urgent patches.
Details of the Vulnerabilities
The first vulnerability, CVE-2026-85102, affects Check Point Security Gateway and Spark Firewall systems using Remote Access VPN or certificate-based Site-to-Site VPN authentication. The flaw arises from inadequate validation of certificate data during VPN negotiations, which could allow attackers to execute arbitrary code without valid credentials. Although Check Point provided a patch on September 9, 2026, exploitation attempts were observed starting September 12, targeting Spark Firewall customers worldwide.
Attackers utilizing this flaw have been using suspicious VPN certificate subjects, though these should not be considered exhaustive. Threat actors may alter certificate subjects in future attacks to evade detection.
Newly Disclosed Zero-Day Threat
The second vulnerability, CVE-2026-93616, is a newly discovered zero-day flaw affecting Check Point’s Security Management and Multi-Domain Security Management environments. It involves a pre-authentication directory traversal and file-upload issue, enabling attackers to upload and execute arbitrary scripts on vulnerable management servers. Check Point has confirmed several real-world attacks targeting this flaw.
This vulnerability affects several Check Point products, including Security Management Server and Multi-Domain Security Management Server. However, Smart-1 Cloud, Check Point Firewall Appliances, and Check Point Spark Firewall are not impacted by this issue.
Mitigation Measures
Organizations using susceptible Check Point products are urged to immediately apply the recommended security patches. For CVE-2026-85102, the LivePatch Take 26 or later Jumbo Hotfix releases offer protection, while for CVE-2026-93616, the R82.20 Security Hotfix or supported Jumbo Hotfix versions are recommended.
Administrators should also monitor Mobile Access logs for unusual VPN login activities and investigate any suspicious actions by newly authenticated users. Internal port scanning or unexpected service discovery following questionable VPN logins could indicate further intrusion attempts. Check Point advises restricting TCP port 19009 access to trusted IP addresses to safeguard management servers.
The active exploitation of these vulnerabilities underscores the critical importance of promptly patching internet-facing VPN and security-management infrastructures. Failure to do so could leave systems vulnerable to exploitation by ransomware operators, access brokers, and state-sponsored threat actors.
