460.23.09.26- Critical Check Point Vulnerabilities Under Active Exploitation – CVE-2026-85102 and CVE-2026-93616

460.23.09.26- Critical Check Point Vulnerabilities Under Active Exploitation – CVE-2026-85102 and CVE-2026-93616

Severity: Critical

CVSS Score: 9.8

Affected Vendor: Check Point Software Technologies

Exploitation Status: Active exploitation observed

Date: 23 September 2026

Overview

The Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT) is advising organizations and system administrators of two (2) critical vulnerabilities affecting Check Point Security Gateway, Spark Firewall and Security Management products.

The vulnerabilities are identified as CVE-2026-85102 and CVE-2026-93616, with both carrying a CVSS score of 9.8 and may allow an unauthenticated remote attacker to compromise affected systems.

Organizations using the affected Check Point products are strongly advised to review their environment and apply the available security fixes immediately as both of the following vulnerabilities are being actively exploited in the wild:

  • CVE-2026-85102One day exploitation- Pre-authentication remote code execution vulnerability in Security Gateway’s VPN certificate handling
  • CVE-2026-85102Zero-day, limited exploitation – Pre-authentication path traversal vulnerability in the Check Point Management web service

Affected Products

CVEAffected ProductsAffected Versions
CVE-2026-85102Security Gateway; Spark Firewall (Centrally Managed); Spark Firewall (Locally Managed)R81 (EOS), R81.10 (EOS), R81.10.X, R81.10.X, R81.20, R82, R82.00.X, R82.00.X, R82.10
CVE-2026-93616Security ManagementR82.20 R82.10 Jumbo Hotfix Take 44 or lower R82 Jumbo Hotfix Take 126 or lower R81.20 Jumbo Hotfix Take 166 or lower R81.10 Jumbo Hotfix Take 190 or lower (EoS) R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)

Administrators should note that Check Point Live Patch Take 28/29 does not remediate CVE-2026-93616.

Indicators and Detection

For CVE-2026-85102, Check Point observed exploitation attempts originating from anonymization infrastructure, including VPN services and proxy networks.

Observed malicious or suspicious certificate subjects include:

CN=vpn,OU=users,O=global

CN=vpn-user,OU=users,O=global

CN=vpnuser,OU=users,O=global

Organizations should review logs for:

  • Unusual certificate-based Mobile Access authentication;
  • Unexpected or unauthorized Mobile Access users;
  • Authentication originating from unusual or anonymized IP addresses;
  • Internal network, port or service scanning following a Mobile Access login;
  • Unusual administrative activity;
  • Unexpected scripts, Java classes or files on Security Management systems;
  • Other anomalous activity occurring before or following suspicious authentication events.

Recommendations

CVE-2026-85102

  • Review your logs for anomalous certificate-based Mobile Access logins.
  • Look for second stage activity originating from suspicious logged-in users via Mobile Access.
  • Apply patches for CVE-2026-85102 via Check Point SK1000117

CVE-2026-93616

  • Limit access to your Management Servers behind a Security Gateway/Check Point Firewall
  • Make sure that access to port TCP/19009 is only possible from Trusted IP addresses.
  • If you already have a Security Gateway / Check Point Firewall with implied rules enabled, make sure your Trusted Clients are limited to trusted internal IP addresses.
  • Apply patches for CVE-2026-93616 via Check Point SK1000171

References