Threat Insight

Active Exploitation of Check Point Security Gateway and Security Management Vulnerabilities

Check Point has issued a security advisory regarding two critical vulnerabilities affecting Check Point Security Gateway and Security Management products. According to Check Point, both vulnerabilities are being actively exploited, and fixes are available for affected systems.

  • Insight
check-point-vulnerability.

CVE-2026-85102 is a pre-authentication remote code execution vulnerability in Security Gateway VPN certificate handling. Fixes were released on September 9, 2026, and exploitation attempts are now being observed globally against Check Point Spark customers.

CVE-2026-93616 is a newly discovered pre-authentication path traversal vulnerability affecting Check Point Security Management. A successful attacker can execute a script from an arbitrary path and load an arbitrary Java class. Check Point identified a limited number of targeted attacks exploiting this vulnerability prior to public disclosure[1].

CVE

CVE-2026-85102

CVE-2026-93616

Affected Products

CVE-2026-85102:
Security Gateway
Spark Firewall (Centrally Managed)
Spark Firewall (Locally Managed)

Affected versions include:
R81 (EoS)
R81.10 (EoS)
R81.10.X
R81.20
R82
R82.00.X
R82.10

CVE-2026-93616:
Security Management Server
Multi-Domain Security Management Server
Log Server
Multi-Domain Log Server
SmartEvent

Affected versions include:
R82.20
R82.10 Jumbo Hotfix Take 44 or lower
R82 Jumbo Hotfix Take 126 or lower
R81.20 Jumbo Hotfix Take 166 or lower
R81.10 Jumbo Hotfix Take 190 or lower (EoS)
R80, R80.10, R80.20, R80.30, R80.40 and R81 (all EoS)

Exploitation

According to Check Point, active exploitation of CVE-2026-85102 has been observed since September 12, 2026, targeting Check Point Spark customers globally. Observed exploitation attempts originated from anonymization infrastructure, including VPN services and proxies[1].

Exploitation of CVE-2026-93616 was observed in a limited number of targeted attacks on July 23, 2026[1].

Recommended Actions

Truesec recommends installing fixes for both vulnerabilities, found here:

https://support.checkpoint.com/results/sk/sk1000117 [2] (CVE-2026-85102)
https://support.checkpoint.com/results/sk/sk1000171/ [3] (CVE-2026-93616)

Furthermore, for CVE-2026-85102, Truesec recommends that you review your logs for anomalous certificate-based Mobile Access logins. Do not limit the search to the subjects above. Look for second stage activity originating from suspicious logged-in users via Mobile Access. Follow-up activity often involves internal port and service scan.

For CVE-2026-93616, there are detailed steps in how you can hunt for potential exploitation on you Security Management Server available in sk1000171, found here: https://support.checkpoint.com/results/sk/sk1000171/.

Detection

For CVE-2026-85102, exploitation attempts originated from anonymization infrastructure, including VPN services and proxies, and used certificates with the following subjects:
CN=vpn,OU=users,O=global
CN=vpn-user,OU=users,O=global
CN=vpnuser,OU=users,O=global

This list is not exhaustive, and other certificate subjects may be in use.

For CVE-2026-93616, you should follow the mitigation and detection steps in sk1000171, found here: https://support.checkpoint.com/results/sk/sk1000171/

References

[1] https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
[2] https://support.checkpoint.com/results/sk/sk1000117/
[3] https://support.checkpoint.com/results/sk/sk1000171/

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights