Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Check Point confirms active exploitation of pre-auth VPN RCE CVE-2026-85102 and zero-day CVE-2026-93616, now both in CISA KEV.
Check Point confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution flaw in Security Gateway VPN certificate handling. The advisory also says CVE-2026-93616, a pre-authentication path traversal in the Management web service that can allow script execution and Java class loading, has been exploited as a zero-day since July 23, 2026. Attempts against Spark customers began on September 12 from VPN and proxy infrastructure, using observed certificate subjects such as CN=vpn, OU=users, O=global. CISA added both vulnerabilities to the KEV catalog and told federal agencies to remediate by September 25, 2026; fixes include LivePatch Take 26 and specified Jumbo Hotfix takes.
- CVE-2026-85102 is pre-auth RCE in VPN certificate handling.
- CVE-2026-93616 has been exploited as a zero-day since July 23.
- Spark exploitation attempts began September 12 via VPNs and proxies.
- CISA added both flaws to KEV with a September 25 deadline.
- Fixes include LivePatch Take 26 and listed Jumbo Hotfix takes.
Vulnerabilities mentionedAll →
- CVE-2026-851029.8<1%Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flawpublished · Check Point Quantum Security Gateway (VPN negotiation functionality) KEV
Full article459 words · extracted from bleepingcomputer.com · click to collapse

Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product.
The same advisory also warns of threat actors exploiting a pre-authentication path traversal flaw tracked as CVE-2026-93616, which impacts the Management web service and can allow script execution and Java class loading.
The company says that CVE-2026-93616 has been exploited as a zero-day since July 23.
On September 10, the Dutch Nationaal Cyber Security Centrum (NCSC) alerted of the Security Gateway issue and urged users to apply available security updates as imminent exploitation was expected.
Check Point has now confirmed that malicious activity started on September 12, with attackers using VPNs and proxies to hide their location.
“Starting September 12, 2026, we observed a wave of exploitation attempts against Spark customers,” reads Check Point’s alert.
“The attempts originated from anonymization infrastructure, including VPN services and proxies," the company said, adding that certificates with the following subjects were used:
- CN=vpn,OU=users,O=global
- CN=vpn-user,OU=users,O=global
- CN=vpnuser,OU=users,O=global
However, the cybersecurity company noted that the three subjects only reflect current observations and more may be in use.
CISA has now added the two flaws in its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to apply the available fixes and/or mitigations by September 25, 2026.
Mitigating the risk
Check Point’s advisory on CVE-2026-85102 recommends that administrators install Check Point LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways, or install a fixed Jumbo Hotfix: R81.20 Take 166, R82 Take 126, R82.10 Take 44, or R81.10 Take 190, or later.
Customers should also update Spark firewalls to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later.
System administrators are advised to verify if LivePatch is active by running the cpinfo -y CPupdates command on the Security Gateway in expert mode.
The advisory specifically warns that some customers who installed an earlier offline LivePatch package need Take 26 for full coverage.
If updating isn’t possible, it is recommended to disable the VPN implied rules and create explicit rules that restrict Site-to-Site VPN on UDP/500 and UDP/4500 to specific peer IP addresses.
For Remote Access VPN, allow only the required services over UDP/500, UDP/4500, TCP/443, and TCP/80 where applicable, and restrict source client IP ranges where possible.
Check Point notes that these mitigation measures do not apply to locally managed Spark firewalls.
For mitigation and hunting advice for the Management web service CVE-2026-93616, Check Point points to this support article.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.