Cybersecurity firm Check Point has issued an advisory confirming that threat actors are actively exploiting a remote code execution vulnerability in the VPN certificate-handling functionality of its Security Gateway product, tracked as CVE-2026-85102.
The same advisory warns of exploitation of a separate pre-authentication path traversal flaw, CVE-2026-93616, which affects the Management web service and can allow script execution and Java class loading. Check Point says this second vulnerability has been exploited as a zero-day since July 23.
According to the company, malicious activity against the Security Gateway flaw began on September 12, with attackers using anonymization infrastructure to hide their location. "Starting September 12, 2026, we observed a wave of exploitation attempts against Spark customers," the alert reads. "The attempts originated from anonymization infrastructure, including VPN services and proxies."
Check Point stated that certificates with the following subjects were used in the attacks: CN=vpn,OU=users,O=global; CN=vpn-user,OU=users,O=global; and CN=vpnuser,OU=users,O=global. The company cautioned that these three subjects reflect only current observations and that more may be in use.
The Dutch Nationaal Cyber Security Centrum (NCSC) had earlier alerted users on September 10 about the Security Gateway issue, warning that imminent exploitation was expected and urging administrators to apply available security updates.
CISA has now added both flaws to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to apply available fixes or mitigations by September 25, 2026.
Mitigations
Check Point's advisory recommends administrators install LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways, or install a fixed Jumbo Hotfix: R81.20 Take 166, R82 Take 126, R82.10 Take 44, or R81.10 Take 190, or later. Customers should also update Spark firewalls to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later.
Administrators are advised to verify whether LivePatch is active by running the cpinfo -y CPupdates command on the Security Gateway in expert mode. The advisory specifically warns that some customers who installed an earlier offline LivePatch package need Take 26 for full coverage.
If updating is not possible, Check Point recommends disabling the VPN implied rules and creating explicit rules that restrict Site-to-Site VPN on UDP/500 and UDP/4500 to specific peer IP addresses. For Remote Access VPN, administrators should allow only required services over UDP/500, UDP/4500, TCP/443, and TCP/80 where applicable, and restrict source client IP ranges where possible. The company notes these mitigation measures do not apply to locally managed Spark firewalls.