Hackers Exploit Critical Check Point VPN Flaws to Gain Remote Access Without Login
Check Point confirms active exploitation of two CVSS 9.8 VPN and management flaws enabling unauthenticated code execution.
Check Point says attackers are exploiting two CVSS 9.8 vulnerabilities that allow unauthenticated remote access and possible remote code execution. CVE-2026-85102, patched September 9, 2026, stems from improper VPN certificate validation on Security Gateway and Spark Firewall; exploitation attempts against Spark customers began September 12 from VPN and proxy infrastructure. Newly disclosed zero-day CVE-2026-93616 is a pre-authentication directory traversal and file-upload flaw in Security Management and Multi-Domain Security Management, with a handful of customers targeted. Smart-1 Cloud, firewall appliances, and Spark are not affected by the management flaw; R82.20 is unaffected by the VPN issue.
- CVE-2026-85102 allows unauthenticated code execution during VPN certificate negotiation.
- Spark Firewall exploitation attempts began September 12 from anonymizing infrastructure.
- CVE-2026-93616 is a pre-auth traversal and file-upload flaw on management servers.
- Both issues score CVSS 9.8; a handful of customers were targeted.
- LivePatch Takes 28 and 29 do not fix CVE-2026-93616.
Vulnerabilities mentionedAll →
- CVE-2026-851029.8<1%Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flawpublished · Check Point Quantum Security Gateway (VPN negotiation functionality) KEV
Full article615 words · extracted from cybersecuritynews.com · click to collapse
Check Point has warned that attackers are actively exploiting two critical vulnerabilities in its VPN and management products, allowing unauthenticated remote access and possible remote code execution.
Both flaws carry a CVSS severity score of 9.8, and the company has released fixes that affected organizations should apply immediately.
The first issue, tracked as CVE-2026-85102, affects Check Point Security Gateway and Spark Firewall deployments that use Remote Access VPN or certificate-based Site-to-Site VPN authentication.
The flaw stems from improper validation of certificate data during VPN negotiation, which can allow a remote attacker to execute arbitrary code without valid credentials.
Check Point released a patch for CVE-2026-85102 on September 9, 2026. At that time, the company had not identified exploitation activity.
Check Point VPN Flaws Exploit
However, Check Point later confirmed that attackers began attempting to exploit the vulnerability against Spark Firewall customers from September 12. The attacks were observed globally and originated from anonymization infrastructure, including VPN services and proxy networks.
Attackers used suspicious VPN certificate subject values such as CN=vpn, OU=users, O=global; CN=vpn-user, OU=users, O=global; and CN=vpnuser, OU=users, O=global. These indicators should not be treated as a complete detection list, as threat actors may use different certificate subjects in future attempts.
The second flaw is a newly disclosed zero-day vulnerability (CVE-2026-93616) affecting Check Point Security Management and Multi-Domain Security Management environments.
It is a pre-authentication directory traversal and file-upload issue that can enable an attacker to upload and execute arbitrary scripts on an exposed management server. Check Point said it knows of a handful of customers targeted in real-world attacks.
CVE-2026-93616 affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products. Smart-1 Cloud, Check Point Firewall Appliances, and Check Point Spark Firewall are not affected by this management-server vulnerability.
The flaw can allow an unauthenticated attacker to abuse directory traversal sequences, such as ../, to access unintended paths and load attacker-controlled content.
In practical terms, successful exploitation could give an intruder a path to execute malicious scripts on a highly privileged management platform, creating risks of firewall policy manipulation, credential theft, network reconnaissance, and lateral movement.
Organizations using vulnerable Check Point products should install the available Jumbo Hotfixes or security hotfixes without delay.
For CVE-2026-85102, Check Point protects LivePatch Take 26 or later supported Jumbo Hotfix releases. The company notes that R82.20 is not affected by this VPN issue.
For CVE-2026-93616, administrators should update to the R82.20 Security Hotfix or supported Jumbo Hotfix versions. Check Point said LivePatch Take 28 and Take 29 do not address this vulnerability, and a LivePatch is not available because of the nature of the required fix.
Administrators should review Mobile Access logs for anomalous certificate-based VPN logins and investigate suspicious activity performed by newly authenticated users.
Internal port scanning or service discovery after a questionable VPN login may indicate second-stage intrusion activity. For management servers, Check Point recommends restricting TCP port 19009 access to trusted IP addresses only.
Security teams should also inspect management logs for unusually long usernames, error messages involving ReflectionUtils, and file paths containing directory traversal patterns. These artifacts may signal an attempted exploit against CVE-2026-93616.
The active exploitation of both flaws highlights the continuing value of patching internet-facing VPN and security-management infrastructure quickly.
These systems often sit at the network perimeter or control critical security policies, making them high-value targets for ransomware operators, access brokers, and state-backed threat actors.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.