Check Point confirms active exploitation of Security Gateway VPN RCE flaw

Pre-authentication vulnerabilities added to CISA KEV catalog; federal agencies given September 25 deadline to patch

By LineZotpaper
Published
Read Time3 min
Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution vulnerability in the VPN certificate-handling functionality of its Security Gateway product, with attacks observed since September 12. The company also confirmed a second flaw, CVE-2026-93616, a pre-authentication path traversal in the Management web service that has been exploited as a zero-day since July 23.

Cybersecurity firm Check Point has issued an advisory confirming that threat actors are actively exploiting a remote code execution vulnerability in the VPN certificate-handling functionality of its Security Gateway product, tracked as CVE-2026-85102.

The same advisory warns of exploitation of a separate pre-authentication path traversal flaw, CVE-2026-93616, which affects the Management web service and can allow script execution and Java class loading. Check Point says this second vulnerability has been exploited as a zero-day since July 23.

According to the company, malicious activity against the Security Gateway flaw began on September 12, with attackers using anonymization infrastructure to hide their location. "Starting September 12, 2026, we observed a wave of exploitation attempts against Spark customers," the alert reads. "The attempts originated from anonymization infrastructure, including VPN services and proxies."

Check Point stated that certificates with the following subjects were used in the attacks: CN=vpn,OU=users,O=global; CN=vpn-user,OU=users,O=global; and CN=vpnuser,OU=users,O=global. The company cautioned that these three subjects reflect only current observations and that more may be in use.

The Dutch Nationaal Cyber Security Centrum (NCSC) had earlier alerted users on September 10 about the Security Gateway issue, warning that imminent exploitation was expected and urging administrators to apply available security updates.

CISA has now added both flaws to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to apply available fixes or mitigations by September 25, 2026.

Mitigations

Check Point's advisory recommends administrators install LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways, or install a fixed Jumbo Hotfix: R81.20 Take 166, R82 Take 126, R82.10 Take 44, or R81.10 Take 190, or later. Customers should also update Spark firewalls to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later.

Administrators are advised to verify whether LivePatch is active by running the cpinfo -y CPupdates command on the Security Gateway in expert mode. The advisory specifically warns that some customers who installed an earlier offline LivePatch package need Take 26 for full coverage.

If updating is not possible, Check Point recommends disabling the VPN implied rules and creating explicit rules that restrict Site-to-Site VPN on UDP/500 and UDP/4500 to specific peer IP addresses. For Remote Access VPN, administrators should allow only required services over UDP/500, UDP/4500, TCP/443, and TCP/80 where applicable, and restrict source client IP ranges where possible. The company notes these mitigation measures do not apply to locally managed Spark firewalls.

§

Analysis

Why This Matters

  • Both vulnerabilities are pre-authentication, meaning attackers need no credentials to exploit them, and one (CVE-2026-93616) has been actively exploited since July 23.
  • CISA has mandated federal agencies patch by September 25, reflecting the severity of the active exploitation.
  • Organizations using Check Point Security Gateway and Spark firewalls face direct exposure if updates are not applied promptly.

Background

Check Point Security Gateway is a widely deployed enterprise firewall and VPN product. The two flaws are distinct: CVE-2026-85102 is a remote code execution issue in VPN certificate handling, while CVE-2026-93616 is a path traversal in the Management web service. The Dutch NCSC flagged imminent exploitation on September 10, and attacks were confirmed two days later, originating from VPN and proxy infrastructure consistent with anonymized attacker operations.

Key Perspectives

Check Point (vendor): Has confirmed the exploitation, released fixed versions and LivePatch updates, and provided interim mitigation guidance for organizations unable to patch immediately. Regulators (CISA, Dutch NCSC): Both have treated the vulnerabilities as urgent, with CISA adding them to the KEV catalog and setting a September 25 federal deadline, and the NCSC warning early that exploitation was imminent. Critics/Skeptics: The delay between the July zero-day exploitation of CVE-2026-93616 and public confirmation of active attacks may raise questions about disclosure timing. The company's own caveat that observed certificate subjects reflect only current attacks suggests visibility into the full scope may be incomplete.

What to Watch

  • Whether CISA's September 25 deadline drives rapid patch adoption across federal agencies and whether additional exploitation is reported before then.
  • Whether new or additional certificate subjects appear in attack traffic, indicating broader or more varied exploitation.
  • Whether attackers shift to the Management web service vector now that the Security Gateway issue is publicly documented.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.