Executive Summary
Check Point Software Technologies has confirmed active exploitation of two critical CVSS 9.8 vulnerabilities affecting Security Gateway / Spark and Security Management infrastructure. Both were added to the CISA Known Exploited Vulnerabilities catalog on September 22, 2026, with a federal remediation due date of September 25, 2026, forensic triage required = Yes, and known ransomware campaign use = Unknown.
CVE-2026-85102 is improper certificate validation during VPN negotiation that can allow unauthenticated remote code execution on Security Gateway and Spark Firewall when Site-to-Site VPN or Remote Access VPN is in use (CWE-295). Fixes were released September 9, 2026; Check Point reports a wave of exploitation attempts against Spark customers beginning September 12, 2026. Vendor materials do not confirm whether any 85102 attempt succeeded.
CVE-2026-93616 is a pre-authentication directory traversal and file upload flaw in the Management web service that can allow arbitrary-path script execution and arbitrary Java class load (CWE-22). It affects Security Management Server, Multi-Domain Security Management, Log Server, Multi-Domain Log Server, and SmartEvent. Check Point Research observed a handful of pinpointed exploitation attempts as early as July 23, 2026 (zero-day at the time). Smart-1 Cloud and Check Point Firewall / Spark appliances are not affected by 93616 per sk1000171.
Operators must patch both planes separately: LivePatch Take 26 / Jumbo takes for 85102 do not fix 93616, and LivePatch Take 28/29 (for a different issue) does not fix 93616 either.
Technical Information
CVE-2026-85102 — Gateway / Spark VPN certificate RCE
Improper certificate trust validation during VPN negotiation may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway (NVD / vendor). Scope centers on certificate-based authentication for Site-to-Site VPN or Remote Access VPN. Per sk1000117: DAIP/LSV communities enable cert auth; PSK-only encryption communities are not vulnerable. Temporary mitigations if patching is delayed include restricting implied VPN rules and explicitly allowing S2S UDP/500 and UDP/4500 to peer IPs (and for RA VPN also TCP/443 and TCP/80 where applicable)—not for locally managed Spark.
Check Point reports Spark-focused exploitation attempts from September 12, 2026 using anonymizing infrastructure, with observed malicious certificate subjects (non-exhaustive). Follow-on behavior described: anomalous certificate-based Mobile Access logins and second-stage internal port/service scanning from suspicious Mobile Access users.
CVE-2026-93616 — Management plane pre-auth path traversal
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server (NVD). Vendor framing also includes arbitrary Java class load. Exposure guidance (sk1000171): keep Management access behind Gateway/Firewall; ensure TCP/19009 only from trusted IPs; use Trusted Clients restrictions in SmartConsole.
Check Point Research observed pinpointed exploitation attempts on July 23, 2026. Post-exploitation payload details are not publicly disclosed.
Primary sources reviewed (Check Point blog/SKs, CISA KEV, NVD) do not explicitly map either CVE to MITRE ATT&CK technique IDs. This advisory does not invent ATT&CK mappings or APT attribution.
Affected Product Versions
Vendor: Check Point Software Technologies.
CVE-2026-85102 (Gateway / Spark)
Affected products: Security Gateway; Spark Firewall (Centrally Managed); Spark Firewall (Locally Managed) when using Site-to-Site VPN or Remote Access VPN.
Affected versions (vendor blog / sk1000117): R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10; sk1000117 also lists R80–R80.40. Not affected: R82.20.
NVD CPE notes Quantum Security Gateway Jumbo thresholds (R82.10 Take ≤43, R82 ≤125, R81.20 ≤165) and Gaia / Gaia Embedded (Spark) builds.
CVE-2026-93616 (Management / Log / SmartEvent)
Affected products (sk1000171): Security Management Server; Multi-Domain Security Management Server; Log Server; Multi-Domain Log Server; SmartEvent.
Not affected (sk1000171): Smart-1 Cloud (fix already applied); Check Point Firewall Appliances; Check Point Spark Firewall.
Affected versions (sk1000171 / vendor blog):
- R82.20
- R82.10 Jumbo Hotfix Take 44 or lower
- R82 Jumbo Hotfix Take 126 or lower
- R81.20 Jumbo Hotfix Take 166 or lower
- R81.10 Jumbo Hotfix Take 190 or lower (EoS)
- R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)
Critical: LivePatch Take 28/29 does not address CVE-2026-93616. LivePatch is not available for this issue.
Workaround and Mitigation
CVE-2026-85102
- Apply LivePatch Take 26 for R82.10 / R82 / R81.20 (auto or offline; validate with cpinfo -y CPupdates / cplp list).
- Or Jumbo Hotfix: R82.10 from Take 44; R82 from Take 126; R81.20 from Take 166; R81.10 from Take 190.
- Spark: R82.00.10 from Build 2325; R81.10.17 from Build 4968.
- If patching is delayed: disable VPN implied rules; explicit S2S UDP/500+4500 to peer IPs; RA VPN explicit rules (UDP/500, UDP/4500, TCP/443, TCP/80)—not for locally managed Spark.
- Hunt anomalous certificate-based Mobile Access logins since 2026-09-12 (not limited to the three published cert subjects).
CVE-2026-93616
- Apply R82.20 Security Hotfix (TAR) or Jumbo: R82.10 from Take 45; R82 from Take 127; R81.20 from Take 170; R81.10 from Take 192 (these Jumbos also include CVE-2026-91843).
- Do not treat LivePatch 28/29 as a fix for 93616.
- Limit Management access; ensure TCP/19009 only from trusted IPs; Trusted Clients in SmartConsole.
- Run sk1000171 IoC greps on every Mgmt/MDS/Log/MDS Log/SmartEvent node.
Because both CVEs are in CISA KEV with due date September 25, 2026 and forensic triage = Yes under BOD 26-04, do not close residual risk on “patched” alone—complete IoC hunts and exposure attestation for both VPN and management planes.
Indicators of Compromise
No malware hashes or exploit binaries are published by Check Point or CISA in the sources reviewed. Honest empty for file hashes.
CVE-2026-85102 (vendor blog — non-exhaustive)
Observed malicious certificate subjects:
- CN=vpn,OU=users,O=global
- CN=vpn-user,OU=users,O=global
- CN=vpnuser,OU=users,O=global
Also hunt: anomalous certificate-based Mobile Access logins; second-stage internal port/service scans from suspicious Mobile Access users.
CVE-2026-93616 (sk1000171 — check every Mgmt/MDS/Log/MDS Log/SmartEvent)
- Expert: grep for oversized username login patterns in $MDS_FWDIR/log/cpm.elg* (see sk1000171)—if hit, check coincident FWM/MDS core dumps under /var/log/dump/usermode/.
- Expert: grep for ReflectionUtils / Failed to load allResourceFiles map from errors—review for ../ traversal paths (SK example includes /tmp/003193_VULNCHECK/scripts/upgrade_files.conf).
Do not invent ATT&CK IDs or additional IoCs beyond vendor-published indicators.
References
- Check Point Security Advisory blog (Lotem Finkelstein), 2026-09-22 — https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
- sk1000117 — CVE-2026-85102 — https://support.checkpoint.com/results/sk/sk1000117/
- sk1000171 — CVE-2026-93616 — https://support.checkpoint.com/results/sk/sk1000171/
- CISA: Adds Four Known Exploited Vulnerabilities to Catalog, 2026-09-22 — https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog
- CISA KEV catalog / JSON feed — https://www.cisa.gov/known-exploited-vulnerabilities-catalog ; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- CISA BOD 26-04 / forensics triage — https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- NVD: CVE-2026-85102 — https://nvd.nist.gov/vuln/detail/CVE-2026-85102
- NVD: CVE-2026-93616 — https://nvd.nist.gov/vuln/detail/CVE-2026-93616
- BleepingComputer: Check Point warns of hackers exploiting Security Gateway VPN RCE flaw, 2026-09-23 — https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/
- The Hacker News: Check Point warns of Management Server vulnerability, 2026-09-22 — https://thehackernews.com/2026/09/check-point-warns-of-management-server.html
Third-Party Risk Bridge: Gateway VPN and Management as Dual Control Planes
Check Point Security Gateway and Spark sit on customer and often MSP-managed perimeters; Security Management / MDS / Log / SmartEvent is the policy and logging control plane for fleets of those gateways. CVE-2026-85102 is pre-auth RCE via VPN certificate negotiation; CVE-2026-93616 is pre-auth path traversal on management—together they are TPRM control-plane assets, not one ticket. Ask every MSP or colo provider: Are Gateways/Spark on LivePatch Take 26 or Jumbo takes ≥44/126/166/190 (Spark builds ≥2325/4968)? Is certificate-based VPN in use, and were Mobile Access cert logins reviewed since 2026-09-12? Is Management/TCP/19009 internet-exposed, and are Jumbo takes at ≥45/127/170/192 (not LivePatch 28/29 mistaken for a 93616 fix)? Both CVEs entered CISA KEV on September 22, 2026 with due September 25, 2026 and forensic triage required—treat patch evidence plus IoC hunts as the close criteria.
Book a demo to see how Rescana tracks edge and management-plane vendors for dual KEV exposure, version attestation, and forensic-triage evidence.
Forward this advisory to your TPRM owner if an MSP or third party operates Check Point Gateways, Spark, or Security Management for your estate—they own the dual-plane patch takes, VPN/management exposure, and IoC-hunt attestation asks above.



