An organization’s VPN gateway and its security-management server are different trust boundaries. In a September 22 advisory, Check Point reported active exploitation of two critical, pre-authentication flaws: CVE-2026-85102 in VPN certificate handling on Security Gateway and Spark Firewall, and CVE-2026-93616 in a Security Management web service. Installing a fix for one component does not establish that the other is protected. A firewall in front of the management server can narrow who reaches it; it does not repair vulnerable code.
The immediate work is to inventory both roles, obtain the branch-specific fix from Check Point, verify the installed result, and investigate activity while the systems were exposed. Check Point assigns each flaw a CVSS score of 9.8 and says it observed exploitation. CISA listed both CVEs in its Known Exploited Vulnerabilities catalog on September 22. The public advisory does not provide a complete exploit chain or a universal IOC that can clear every appliance.
Two Flaws, Two Exposure Questions
| Flaw | What Check Point says | First exposure question |
|---|---|---|
| CVE-2026-85102 | Improper handling of certificate data during VPN negotiation permits unauthenticated remote code execution. Check Point disclosed a fix on September 9 and reports exploitation attempts against Spark customers beginning September 12. | Which Security Gateway or Spark appliances run affected software and accept relevant VPN traffic? |
| CVE-2026-93616 | A pre-authentication path traversal in the Security Management web service can lead to arbitrary-path script execution and Java class loading. Check Point says it saw a small number of pinpointed attacks on July 23, before the September 22 fix. | Which management servers run affected hotfix takes, and from where can the management web service be reached? |
Those dates are Check Point’s reported observations, not proof that exploitation was limited to those days or customers. Do not call the two CVEs a single “VPN zero-day”: the management flaw is a distinct service with a distinct patch history. Check Point advisory
Establish the Affected Population
The gateway issue covers Check Point’s listed Security Gateway and Spark Firewall releases across R81, R81.10, R81.10.X, R81.20, R82, R82.00.X, and R82.10. The exact fixed build depends on branch and appliance; use sk1000117 for the current patch and validation steps. Unsupported R81 and R81.10 installations need a supported remediation path, not a guess based on a neighboring release. Check Point affected-version table
For CVE-2026-93616, Check Point lists Security Management on R82.20, R82.10 Jumbo Hotfix Take 44 or lower, R82 Take 126 or lower, R81.20 Take 166 or lower, and R81.10 Take 190 or lower, plus older end-of-support R80/R81 branches. These are affected ranges, not a complete table of validated fixed takes. Check Point directs customers to sk1000171 for the exact fixes and verification. Crucially, the vendor says LivePatch Take 28/29 does not fix the management flaw. Do not accept a LivePatch label alone as evidence that CVE-2026-93616 is closed. Check Point advisory
The network and platform owners should reconcile the asset list against internet addresses, VPN endpoints, centrally and locally managed Spark appliances, Security Management servers, standby systems, and disaster-recovery instances. For each, record product role, release, installed Jumbo Hotfix or LivePatch, management reachability, patch owner, and last successful check-in. Check Point’s fw ver reference describes the read-only version command for gateways:
fw verThe major version and build from that command are not a substitute for checking the installed hotfix take. Use the vendor’s branch-specific validation procedure and the management interface to confirm the running fix on each component. Do not apply a gateway result to the management server or vice versa.
Patch, Contain, Verify
| Owner | Preventive action | Observable verification |
|---|---|---|
| Gateway and Spark owners | Install the applicable fix for CVE-2026-85102 from sk1000117. Plan a maintenance window and confirm VPN and policy traffic after restart. If patching is delayed, restrict unnecessary VPN reachability only where business requirements allow; this reduces exposure but is not a vendor-declared substitute for the fix. | Record the running release and installed fix per appliance, then test legitimate VPN access and policy enforcement. Check standby and recovery appliances separately. |
| Management-server owners | Install the branch-specific CVE-2026-93616 fix from sk1000171. Where necessary before patching, restrict the management service at the network layer to approved jump hosts and admin ranges. Keep required management communication working. | Confirm the fixed take or hotfix using Check Point’s validation steps and test management access from an approved host and a disallowed network. |
| Security architects | Maintain a narrow management plane after the patch. Check Point’s hardening guide recommends limiting SmartConsole, Gaia Portal, SSH, and API access to specific internal ranges or jump hosts. Its Trusted Clients guidance adds a SmartConsole control; verify that the vulnerable web service itself is covered by network restrictions rather than assuming Trusted Clients governs it. | An external reachability test shows no unapproved path to the management web service, while required administrative and gateway-management flows still work. |
MFA can reduce account abuse, but these are pre-authentication vulnerabilities. It does not remove either exploit prerequisite. Monitoring and IOC searches are also insufficient as substitutes for the fixes.
Investigate the Window Before the Patch
For CVE-2026-85102, Check Point advises reviewing anomalous certificate-based Mobile Access logins and activity after those logins, including internal port and service scans. It reports subjects such as CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global, and CN=vpnuser,OU=users,O=global in observed attempts. These are leads, not a complete signature: other subjects may be used, and a matching string alone does not prove successful exploitation. Correlate with connection time, source, authentication outcome, sessions, policy changes, and subsequent internal access. Check Point observed-attacks section
For CVE-2026-93616, preserve management-server web and system logs, administrative audit trails, changes to policies and trust relationships, new files, and unexpected outbound traffic. Check Point refers customers to sk1000171 for specific hunting steps and indicators; do not invent an exploit URL or claim that a clean generic scan excludes compromise. The vendor’s July 23 observation means responders should include the pre-disclosure period when retention allows. If evidence points to compromise, use the incident-response process to preserve data, assess management credentials and policy integrity, contain the affected service, and rebuild trust in the managed environment before returning it to service.
The patch plan is complete only when both product roles have been checked against their own fix guidance and any suspected pre-patch activity has been investigated. An updated gateway cannot compensate for an exposed management server.
For a separate edge-appliance case with different CVEs and fixes, see our Citrix NetScaler patch and compromise-check guide.
Sources
- Check Point: September 22 advisory and observed exploitation
- Check Point: CVE-2026-85102 fix and validation, sk1000117
- Check Point: CVE-2026-93616 fix and investigation, sk1000171
- Check Point: management-plane hardening
- Check Point: administrator access and Trusted Clients
- CISA: Known Exploited Vulnerabilities catalog
Useful read?
Find us again on Google.
Add Hive Security as a preferred source for practical security research and analysis.
Add as a preferred source on GoogleChoose Hive Security in Google's source preferences.