Active Exploitation of Check Point Security Gateway and Security Management Vulnerabilities

CVE-2026-85102 is a pre-authentication remote code execution vulnerability in Security Gateway VPN certificate handling. Fixes were released on September 9, 2026, and exploitation attempts are now being observed globally against Check Point Spark customers.

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

CVE-2026-93616 is a newly discovered pre-authentication path traversal vulnerability affecting Check Point Security Management. A successful attacker can execute a script from an arbitrary path and load an arbitrary Java class. Check Point identified a limited number of targeted attacks exploiting this vulnerability prior to public disclosure[1].

CVE

CVE-2026-85102

CVE-2026-93616

Affected Products

CVE-2026-85102:
Security Gateway Spark Firewall (Centrally Managed)
Spark Firewall (Locally Managed)

Affected versions include:
R81 (EoS)
R81.10 (EoS)
R81.10.X
R81.20
R82
R82.00.X
R82.10

CVE-2026-93616:
Security Management Server
Multi-Domain Security Management Server
Log Server Multi-Domain
Log Server SmartEvent

Affected versions include:
R82.20
R82.10 Jumbo Hotfix Take 44 or lower
R82 Jumbo Hotfix Take 126 or lower
R81.20 Jumbo Hotfix Take 166 or lower
R81.10 Jumbo Hotfix Take 190 or lower (EoS)
R80, R80.10, R80.20, R80.30, R80.40 and R81 (all EoS)

Exploitation

According to Check Point, active exploitation of CVE-2026-85102 has been observed since September 12, 2026, targeting Check Point Spark customers globally. Observed exploitation attempts originated from anonymization infrastructure, including VPN services and proxies[1].

Exploitation of CVE-2026-93616 was observed in a limited number of targeted attacks on July 23, 2026[1].

Recommended Actions

Truesec recommends installing fixes for both vulnerabilities, found here:
https://support.checkpoint.com/results/sk/sk1000117 [2] (CVE-2026-85102)
https://support.checkpoint.com/results/sk/sk1000171/ [3] (CVE-2026-93616)

Furthermore, for CVE-2026-85102, Truesec recommends that you review your logs for anomalous certificate-based Mobile Access logins. Do not limit the search to the subjects above. Look for second stage activity originating from suspicious logged-in users via Mobile Access. Follow-up activity often involves internal port and service scan.

For CVE-2026-93616, there are detailed steps in how you can hunt for potential exploitation on you Security Management Server available in sk1000171, found here: https://support.checkpoint.com/results/sk/sk1000171/.

Detection

For CVE-2026-85102, exploitation attempts originated from anonymization infrastructure, including VPN services and proxies, and used certificates with the following subjects: CN=vpn,OU=users,O=global CN=vpn-user,OU=users,O=global CN=vpnuser,OU=users,O=global This list is not exhaustive, and other certificate subjects may be in use.

For CVE-2026-93616, you should follow the mitigation and detection steps in sk1000171, found here: https://support.checkpoint.com/results/sk/sk1000171/

References

[1] https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
[2] https://support.checkpoint.com/results/sk/sk1000117/
[3] https://support.checkpoint.com/results/sk/sk1000171/

The post Active Exploitation of Check Point Security Gateway and Security Management Vulnerabilities appeared first on Truesec.

Article Link: CVE-2026-85102 & CVE-2026-93616: Active Exploitation of Check Point Security Gateway and Security Management Vulnerabilities - Truesec