Check Point warns of active attacks: two critical flaws require more than patching
CVE-2026-85102 and CVE-2026-93616 are being exploited against Check Point VPN gateways and management servers. Contain exposure, patch and hunt for compromise.
- AUTHOR
- Karol Rapacz / CEO Breachroad · OSCP · PNPT
- PUBLISHED
- 24 September 2026
- READING TIME
- 12 min read
- TOPIC
- Vulnerabilities and CVEs
Check Point has confirmed active exploitation of two critical vulnerabilities in its security products. CVE-2026-85102 affects VPN certificate handling in Security Gateway and Spark devices, while CVE-2026-93616 affects the Security Management web service. Both score 9.8 and can be reached before authentication.
This is a particularly consequential kind of alert: technology intended to protect access to the organisation becomes an entry point. The plan therefore cannot end with a hotfix. The organisation must reduce exposure, update the correct components and determine whether an attacker arrived earlier.
Two flaws in different parts of the architecture
According to Check Point’s advisory, the first flaw results from improper certificate-data validation during VPN negotiation. It enables unauthenticated remote code execution on Security Gateway. A fix has been available since 9 September, and the company has observed exploitation attempts against Spark customers globally since 12 September.
The second flaw is path traversal in the Security Management web service. It allows a script to execute from an arbitrary path and an arbitrary Java class to be loaded. Check Point says it observed a handful of targeted CVE-2026-93616 attacks dating back to 23 July.
Those dates matter. For an exposed service, log review should not begin only on the date the patch was announced.
Who needs to act immediately
CVE-2026-85102 covers named Security Gateway and Spark Firewall releases, including relevant R81, R81.10, R81.20, R82 and appliance variants. CVE-2026-93616 affects Security Management, including unpatched R82.20, R82.10, R82, R81.20 and R81.10 releases and older end-of-support lines listed by the vendor.
The required Jumbo Hotfix Take differs by branch. Do not copy a package number from an arbitrary post: use the official sk1000117 and sk1000171 instructions. Check Point also notes that LivePatch Take 28/29 does not address CVE-2026-93616.
If a managed service provider operates the environment, the customer still needs written confirmation of which devices were checked, which releases were deployed, what period was investigated and whether indicators of compromise were found.
Actions for the first hours
Run three workstreams in parallel.
1. Reduce access
Identify internet-reachable gateways, management servers, log servers and SmartEvent systems. Restrict administrative and affected-service access to trusted addresses and the management network. Apply the control in a way that preserves the response team’s access and the ability to deploy the fix safely.
2. Install the correct fixes
Back up configuration under the vendor procedure, obtain the package through the official channel, confirm release compatibility and verify deployment after restart. Cover every cluster node. A ticket marked “installed” is not a substitute for reading the release level from the device.
3. Hunt for earlier access
For CVE-2026-85102, Check Point recommends reviewing anomalous certificate-based Mobile Access sign-ins and second-stage behaviour such as internal port and service scanning. The vendor provides example certificate subjects but says the list is not exhaustive.
For CVE-2026-93616, use the hunting guidance and indicators in the official SK. Review management-service access, script creation and execution, class loading, policy, object and account changes, and log integrity. Patching closes the vulnerability but does not remove persistence established before deployment.
Why management-server compromise is serious
The management server is where policies and objects controlling gateways are created. Compromise does not automatically prove control of every firewall, but it undermines confidence in configuration, policy distribution and the evidence retained in logs.
Determine which credentials, keys and configuration backups were accessible from the server. Compare current policies with approved state, change history and an independent copy. If host integrity cannot be established, consider a rebuild from a trusted source with the vendor or incident-response team.
A message for leadership and users
Most employees do not need the CVE detail. Leadership needs a concise statement: which services are affected, whether they were internet-exposed, whether the fix is deployed, what period is being investigated and whether remote access or continuity may be affected.
Tell VPN users only what they must do, such as signing in again or preparing for a maintenance interruption. If the investigation identifies credential theft or internal movement, communication and access resets should follow the incident procedure rather than an uncoordinated company-wide password change.
Source facts and Breachroad assessment
Check Point confirms two 9.8 vulnerabilities, available fixes and active exploitation. It describes a wave of CVE-2026-85102 attempts and a small number of targeted CVE-2026-93616 attacks. That does not mean every customer was attacked.
Parallel containment, patching, hunting, policy-integrity review and business communication are Breachroad recommendations. Our earlier CVE-2026-16232 SmartConsole analysis covers another issue in the same product family. Organisations can rehearse technical and business roles through cybersecurity training and validate exposure and update governance with an IT security audit.


