Threat Insight
Active Exploitation of Check Point Security Gateway and Security Management Vulnerabilities
Check Point has issued a security advisory regarding two critical vulnerabilities affecting Check Point Security Gateway and Security Management products. According to Check Point, both vulnerabilities are being actively exploited, and fixes are available for affected systems.
CVE-2026-85102 is a pre-authentication remote code execution vulnerability in Security Gateway VPN certificate handling. Fixes were released on September 9, 2026, and exploitation attempts are now being observed globally against Check Point Spark customers.
CVE-2026-93616 is a newly discovered pre-authentication path traversal vulnerability affecting Check Point Security Management. A successful attacker can execute a script from an arbitrary path and load an arbitrary Java class. Check Point identified a limited number of targeted attacks exploiting this vulnerability prior to public disclosure[1].
CVE
CVE-2026-85102
CVE-2026-93616
Affected Products
CVE-2026-85102:
Security Gateway
Spark Firewall (Centrally Managed)
Spark Firewall (Locally Managed)
Affected versions include:
R81 (EoS)
R81.10 (EoS)
R81.10.X
R81.20
R82
R82.00.X
R82.10
CVE-2026-93616:
Security Management Server
Multi-Domain Security Management Server
Log Server
Multi-Domain Log Server
SmartEvent
Affected versions include:
R82.20
R82.10 Jumbo Hotfix Take 44 or lower
R82 Jumbo Hotfix Take 126 or lower
R81.20 Jumbo Hotfix Take 166 or lower
R81.10 Jumbo Hotfix Take 190 or lower (EoS)
R80, R80.10, R80.20, R80.30, R80.40 and R81 (all EoS)
Exploitation
According to Check Point, active exploitation of CVE-2026-85102 has been observed since September 12, 2026, targeting Check Point Spark customers globally. Observed exploitation attempts originated from anonymization infrastructure, including VPN services and proxies[1].
Exploitation of CVE-2026-93616 was observed in a limited number of targeted attacks on July 23, 2026[1].
Recommended Actions
Truesec recommends installing fixes for both vulnerabilities, found here:
https://support.checkpoint.com/results/sk/sk1000117 [2] (CVE-2026-85102)
https://support.checkpoint.com/results/sk/sk1000171/ [3] (CVE-2026-93616)
Furthermore, for CVE-2026-85102, Truesec recommends that you review your logs for anomalous certificate-based Mobile Access logins. Do not limit the search to the subjects above. Look for second stage activity originating from suspicious logged-in users via Mobile Access. Follow-up activity often involves internal port and service scan.
For CVE-2026-93616, there are detailed steps in how you can hunt for potential exploitation on you Security Management Server available in sk1000171, found here: https://support.checkpoint.com/results/sk/sk1000171/.
Detection
For CVE-2026-85102, exploitation attempts originated from anonymization infrastructure, including VPN services and proxies, and used certificates with the following subjects:
CN=vpn,OU=users,O=global
CN=vpn-user,OU=users,O=global
CN=vpnuser,OU=users,O=global
This list is not exhaustive, and other certificate subjects may be in use.
For CVE-2026-93616, you should follow the mitigation and detection steps in sk1000171, found here: https://support.checkpoint.com/results/sk/sk1000171/
References
[1] https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
[2] https://support.checkpoint.com/results/sk/sk1000117/
[3] https://support.checkpoint.com/results/sk/sk1000171/
Stay ahead with cyber insights
Newsletter
Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.
Your current browser privacy settings may be preventing this form from loading properly. To continue, please allow cookies/tracking for this site or temporarily disable strict privacy protection, then refresh the page.
If you’re still experiencing issues, please contact us at hello@truesec.com