Hackers Exploit Critical Check Point VPN Flaws to Gain Remote Access Without Login
Check Point confirms active exploitation of two CVSS 9.8 VPN and management flaws enabling unauthenticated code execution.
Check Point says attackers are exploiting two CVSS 9.8 vulnerabilities that allow unauthenticated remote access and possible remote code execution. CVE-2026-85102, patched September 9, 2026, stems from improper VPN certificate validation on Security Gateway and Spark Firewall; exploitation attempts against Spark customers began September 12 from VPN and proxy infrastructure. Newly disclosed zero-day CVE-2026-93616 is a pre-authentication directory traversal and file-upload flaw in Security Management and Multi-Domain Security Management, with a handful of customers targeted. Smart-1 Cloud, firewall appliances, and Spark are not affected by the management flaw; R82.20 is unaffected by the VPN issue.