CISA Warns of Check Point Vulnerabilities Exploited in Attacks (CVE-2026-85102 & CVE-2026-93616)
CISA says two critical Check Point VPN and management flaws are exploited in the wild.
CISA added CVE-2026-85102 and CVE-2026-93616 to the Known Exploited Vulnerabilities catalog and urged patching before September 25, 2026. CVE-2026-85102 (CVSS 9.8) is an authentication bypass and remote code execution flaw in Check Point Remote Access and Site-to-Site VPN caused by improper certificate validation, letting unauthenticated attackers run code on Security Gateway. CVE-2026-93616 (CVSS 9.8) is a directory traversal and file-upload bug that lets unauthenticated attackers upload and execute scripts on the Management Server. Check Point patches are available; Qualys QIDs 388806 and 388699 detect vulnerable assets.
- Both flaws are CVSS 9.8 and added to CISA KEV.
- CVE-2026-85102 allows unauthenticated RCE on VPN Security Gateways.
- CVE-2026-93616 allows unauthenticated script upload on Management Server.
- Patch deadline cited as September 25, 2026; R82.20 fixes the VPN bug.
Vulnerabilities mentionedAll →
- CVE-2026-851029.8<1%Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flawpublished · Check Point Quantum Security Gateway (VPN negotiation functionality) KEV
Full article346 words · extracted from threatprotect.qualys.com · click to collapse
Check Point has two vulnerabilities that are being exploited in the wild, tracked as CVE-2026-85102 & CVE-2026-93616. The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerabilities to its Known Exploited Vulnerabilities Catalog, urging users to patch before September 25, 2026.
CVE-2026-85102: Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN
The vulnerability has a critical severity rating with a CVSS score of 9.8. The vulnerability originates from an improper validation of certificate data during VPN negotiation. Successful exploitation of the vulnerability may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway.
CVE-2026-93616: Directory Traversal and File upload allows execution of arbitrary script on the Management Server
The vulnerability has a critical severity rating with a CVSS score of 9.8. A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on the Check Point Management Server.
Affected Versions
CVE-2026-85102:
Affected Products: Security Gateway, Check Point Spark Firewall using Site-to-Site VPN or Remote Access VPN
Note: For Site-to-Site VPN, the vulnerability affects Security gateways that use or allow certificate-based authentication.
Affected Versions:
- R81.20, R82, R82.10
- R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10 (all EoS)
- R81.10.x, R82.00.x
Not Affected Versions: R82.20
CVE-2026-93616:
Affected Products: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, SmartEvent.
Not Affected Products: Smart-1 Cloud (fix is already applied), Check Point Firewall Appliances, Check Point Spark Firewall.
Affected Versions:
- R82.20
- R82.10 Jumbo Hotfix Take 44 or lower
- R82 Jumbo Hotfix Take 126 or lower
- R81.20 Jumbo Hotfix Take 166 or lower
- R81.10 Jumbo Hotfix Take 190 or lower (EoS)
- R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)
Note: Check Point LivePatch Take 28/29 does not address this issue.
Mitigation
Vendor has released patches to address the vulnerabilities.
For more information, please refer to Check Point security advisories sk1000117 and sk1000171.
Qualys Detection
Qualys customers can scan their devices with QIDs 388806 and 388699 to detect vulnerable assets.
Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.
References
https://support.checkpoint.com/results/sk/sk1000117
https://support.checkpoint.com/results/sk/sk1000171/