Check Point VPN Vulnerabilities Under Active Exploitation: Urgent Patching Advised
Cybersecurity vendor **Check Point** has confirmed active exploitation of two critical vulnerabilities, **CVE-2026-85102** and **CVE-2026-93616**, impacting its Security Gateway and Management Server products. These pre-authentication flaws allow for remote code execution and script execution, posing significant risks to affected organizations. IT security professionals and privacy-conscious users are urged to apply patches immediately.

**Check Point** has issued an urgent advisory confirming active exploitation of a pre-authentication remote code execution (RCE) vulnerability, **CVE-2026-85102**, within the VPN certificate-handling functionality of its Security Gateway product.
Simultaneously, threat actors are also exploiting **CVE-2026-93616**, a pre-authentication path traversal flaw affecting the Management web service. This vulnerability, which allows for script execution and Java class loading, has been exploited as a zero-day since July 23.
### Escalating Threat Landscape
On September 10, the **Dutch Nationaal Cyber Security Centrum (NCSC)** warned of imminent exploitation for the Security Gateway issue, urging users to apply available security updates. **Check Point** has since confirmed that malicious activity began on September 12, with attackers using VPNs and proxies to conceal their origins.
"Starting September 12, 2026, we observed a wave of exploitation attempts against Spark customers," states **Check Point's** alert. "The attempts originated from anonymization infrastructure, including VPN services and proxies."
The company noted that certificates with subjects like `CN=vpn,OU=users,O=global`, `CN=vpn-user,OU=users,O=global`, and `CN=vpnuser,OU=users,O=global` have been observed in these attacks, though more variations may exist.
Both flaws have been added to the **CISA** Known Exploited Vulnerabilities (**KEV**) catalog, mandating federal agencies to apply fixes or mitigations by September 25, 2026.
### Mitigating the Risk
For **CVE-2026-85102**, **Check Point** advises administrators to install **Check Point** LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways, or to install a fixed Jumbo Hotfix: R81.20 Take 166, R82 Take 126, R82.10 Take 44, or R81.10 Take 190, or later. Spark firewalls should be updated to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later.
Administrators can verify LivePatch activity by running the `cpinfo -y CPupdates` command on the Security Gateway in expert mode. It's crucial to note that some customers who installed an earlier offline LivePatch package will need Take 26 for complete coverage.
If immediate updating is not feasible, temporary mitigation includes disabling VPN implied rules and creating explicit rules that restrict Site-to-Site VPN on UDP/500 and UDP/4500 to specific peer IP addresses. For Remote Access VPN, only allow required services over UDP/500, UDP/4500, TCP/443, and TCP/80 where applicable, and restrict source client IP ranges if possible. These mitigation measures do not apply to locally managed Spark firewalls.
For guidance on mitigating and hunting for **CVE-2026-93616** affecting the Management web service, **Check Point** directs users to its dedicated support article.