460.23.09.26- Critical Check Point Vulnerabilities Under Active Exploitation – CVE-2026-85102 and CVE-2026-93616
Severity: Critical
CVSS Score: 9.8
Affected Vendor: Check Point Software Technologies
Exploitation Status: Active exploitation observed
Date: 23 September 2026
Overview
The Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT) is advising organizations and system administrators of two (2) critical vulnerabilities affecting Check Point Security Gateway, Spark Firewall and Security Management products.
The vulnerabilities are identified as CVE-2026-85102 and CVE-2026-93616, with both carrying a CVSS score of 9.8 and may allow an unauthenticated remote attacker to compromise affected systems.
Organizations using the affected Check Point products are strongly advised to review their environment and apply the available security fixes immediately as both of the following vulnerabilities are being actively exploited in the wild:
- CVE-2026-85102 – One day exploitation- Pre-authentication remote code execution vulnerability in Security Gateway’s VPN certificate handling
- CVE-2026-85102– Zero-day, limited exploitation – Pre-authentication path traversal vulnerability in the Check Point Management web service
Affected Products
| CVE | Affected Products | Affected Versions |
| CVE-2026-85102 | Security Gateway; Spark Firewall (Centrally Managed); Spark Firewall (Locally Managed) | R81 (EOS), R81.10 (EOS), R81.10.X, R81.10.X, R81.20, R82, R82.00.X, R82.00.X, R82.10 |
| CVE-2026-93616 | Security Management | R82.20 R82.10 Jumbo Hotfix Take 44 or lower R82 Jumbo Hotfix Take 126 or lower R81.20 Jumbo Hotfix Take 166 or lower R81.10 Jumbo Hotfix Take 190 or lower (EoS) R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS) |
Administrators should note that Check Point Live Patch Take 28/29 does not remediate CVE-2026-93616.
Indicators and Detection
For CVE-2026-85102, Check Point observed exploitation attempts originating from anonymization infrastructure, including VPN services and proxy networks.
Observed malicious or suspicious certificate subjects include:
CN=vpn,OU=users,O=global
CN=vpn-user,OU=users,O=global
CN=vpnuser,OU=users,O=global
Organizations should review logs for:
- Unusual certificate-based Mobile Access authentication;
- Unexpected or unauthorized Mobile Access users;
- Authentication originating from unusual or anonymized IP addresses;
- Internal network, port or service scanning following a Mobile Access login;
- Unusual administrative activity;
- Unexpected scripts, Java classes or files on Security Management systems;
- Other anomalous activity occurring before or following suspicious authentication events.
Recommendations
CVE-2026-85102
- Review your logs for anomalous certificate-based Mobile Access logins.
- Look for second stage activity originating from suspicious logged-in users via Mobile Access.
- Apply patches for CVE-2026-85102 via Check Point SK1000117
CVE-2026-93616
- Limit access to your Management Servers behind a Security Gateway/Check Point Firewall
- Make sure that access to port TCP/19009 is only possible from Trusted IP addresses.
- If you already have a Security Gateway / Check Point Firewall with implied rules enabled, make sure your Trusted Clients are limited to trusted internal IP addresses.
- Apply patches for CVE-2026-93616 via Check Point SK1000171
References
- Check Point Security Advisory – Active Exploitation of CVE-2026-85102 and CVE-2026-93616 Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616 – Check Point Blog
- Check Point Security Knowledge Base – SK1000117 https://support.checkpoint.com/results/sk/sk1000117/
- Check Point Security Knowledge Base – SK1000171 https://support.checkpoint.com/results/sk/sk1000171/