Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Check Point confirms active exploitation of pre-auth VPN RCE CVE-2026-85102 and zero-day CVE-2026-93616, now both in CISA KEV.
Check Point confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution flaw in Security Gateway VPN certificate handling. The advisory also says CVE-2026-93616, a pre-authentication path traversal in the Management web service that can allow script execution and Java class loading, has been exploited as a zero-day since July 23, 2026. Attempts against Spark customers began on September 12 from VPN and proxy infrastructure, using observed certificate subjects such as CN=vpn, OU=users, O=global. CISA added both vulnerabilities to the KEV catalog and told federal agencies to remediate by September 25, 2026; fixes include LivePatch Take 26 and specified Jumbo Hotfix takes.