CVE-2026-85102 & CVE-2026-93616 (CVSS 9.8): Check Point VPN Zero-Days Under Active Attack — CISA Deadline Is Today
Today, September 25, 2026, is the day CISA set for all U.S. Federal Civilian Executive Branch agencies to have patched two critical Check Point Security Gateway vulnerabilities. If your organisation uses Check Point’s Quantum or Spark firewall products and you have not yet applied the relevant hotfixes, you are running a device that can be silently compromised — without a single login credential — by anyone on the internet who can reach your VPN endpoint.
These are not theoretical. Active exploitation of CVE-2026-85102 began on September 12, 2026, and the companion management-plane flaw CVE-2026-93616 was exploited in the wild as far back as July 23, 2026 — a full two months before most organisations were aware there was a problem. Both carry a CVSS score of 9.8. The time to act is right now.
- CVE-2026-85102 (CVSS 9.8): Pre-authentication RCE in VPN certificate handling on Check Point Security Gateway and Spark Firewall — no credentials needed.
- CVE-2026-93616 (CVSS 9.8): Directory traversal + arbitrary script execution on the Security Management Server — one hit can compromise your entire gateway estate.
- Active exploitation confirmed by Check Point since September 12; management flaw exploited since July 23.
- CISA added both to its Known Exploited Vulnerabilities catalog on September 22; federal deadline is today.
- Affected: Security Gateway R81.10, R81.20, R82, R82.10 and Spark Firewall. R82.20 is not affected.
- Fix: LivePatch Take 26 or the appropriate Jumbo Hotfix for your release train.
What Happened: A Two-Wave Zero-Day Campaign
Check Point’s incident response team pieced together a picture of two overlapping attack campaigns that exploited different surfaces of the same product family.
The first wave targeted the Security Management Server. CVE-2026-93616 is a directory traversal vulnerability in the Management web service that allows an unauthenticated attacker to upload and execute arbitrary scripts on the server hosting your firewall policy. Because the Management Server distributes policy to every gateway it manages, a single successful exploitation could pivot to estate-wide compromise. Forensic telemetry shows “pinpointed exploitation attempts” beginning as early as July 23, 2026, months before the vulnerability was publicly documented.
The second wave hit the gateway itself. CVE-2026-85102 is an improper certificate trust validation flaw triggered during VPN negotiation. When a remote attacker sends a crafted X.509 certificate to an exposed VPN endpoint, the gateway processes it before any authentication check occurs, allowing arbitrary code to execute as root. Exploitation here was confirmed from September 12, 2026 onwards, with attackers routing their traffic through VPN services and proxies to obscure their origin. Certificates bearing subjects like CN=vpn and CN=vpn-user were observed in the wild.
On September 10, the Dutch National Cyber Security Centre (NCSC) issued a pre-emptive alert warning that exploitation of the VPN flaw was imminent. Two days later, Check Point confirmed active attacks against Spark customers. By September 22, CISA had formally added both CVEs to its KEV catalogue under Binding Operational Directive 26-04, with a remediation deadline of September 25 — today.
Technical Breakdown: How the Exploits Work
Understanding why these vulnerabilities are so severe requires a brief look at the certificate validation lifecycle in a VPN gateway.
In an IKEv2 or SSL-VPN handshake, the gateway receives a peer certificate before it can validate identity. In a correctly implemented system, any malformed or untrusted certificate should be rejected immediately. CVE-2026-85102 represents a failure at this pre-authentication boundary: the certificate parsing logic — specifically, the ASN.1 decoding of the certificate fields — processes attacker-controlled data before the trust decision is made. The related CVE-2026-85103 (also CVSS 9.8, identified in some analyses) involves a heap-based buffer overflow in this same ASN.1 decoding path, enabling reliable code execution on the gateway appliance.
The management flaw (CVE-2026-93616) operates differently. The Management Server exposes a web service for administrative operations. The directory traversal allows an unauthenticated HTTP request to escape the intended service root, place arbitrary files on the filesystem, and trigger their execution. The consequence is that the attacker owns the policy engine — meaning they can silently push policy changes to every gateway the Management Server controls, turning your entire perimeter into an open door.
| CVE | CVSS | Affected Component | Exploit Type | Auth Required |
|---|---|---|---|---|
| CVE-2026-85102 | 9.8 Critical | Security Gateway, Spark Firewall | RCE via crafted VPN certificate | None |
| CVE-2026-93616 | 9.8 Critical | Security Management Server | Directory traversal + script exec | None |
Forensic analysis is critical: LivePatch Take 28/29 does NOT address CVE-2026-93616. You must apply management-side patches separately. Organisations that apply only the gateway LivePatch and consider themselves done are still exposed on the management plane.
Why This Matters for India’s Enterprise and Government Networks
Check Point’s Quantum Security Gateway is widely deployed in Indian banking, government, and enterprise environments — particularly in network segments where legacy procurement cycles have maintained long-running R81.10 and R81.20 deployments. The management flaw is especially worrying for Managed Security Service Providers (MSSPs) and NOC/SOC teams operating multi-tenant environments: a single compromised Management Server could cascade across dozens of client estates.
India’s CERT-In expects all critical information infrastructure operators to remediate exploited vulnerabilities within six hours of the advisory under the 2022 directive. With CISA confirmation of active exploitation and a public KEV listing, there is no question about the urgency classification. Any Check Point customer in India that has not yet patched should treat this as a P0 incident.
There is also a broader lesson here about network segmentation and zero-trust architecture. Both attack vectors target externally exposed services: VPN endpoints (CVE-2026-85102) and the Management Server’s web interface (CVE-2026-93616). In a properly segmented zero-trust architecture, the Management Server should never be reachable from the internet — and VPN gateway IKE ports should be restricted to known peer ranges. Many compromised organisations in this campaign had management interfaces directly internet-exposed, an architectural risk that no patch can fix after the fact.
What You Should Do Right Now
Here is the prioritised action checklist. Work through it in order.
- Identify your release train immediately. Run
clish -c "show version product"on each gateway. If you are on R82.20, you are not affected. For all other supported releases (R81.10, R81.20, R82, R82.10), proceed immediately. - Apply LivePatch Take 26 (or the specific Jumbo Hotfix for your release: R81.20 Take 166+, R82 Take 126+, R82.10 Take 44+, R81.10 Take 190+). For Spark Firewalls, update to Build 2325 (R82) or Build 4968 (R81.10).
- Patch the Management Server separately. CVE-2026-93616 is NOT covered by gateway LivePatches. Apply the dedicated management fix and verify the management web service is not internet-exposed. This is non-negotiable.
- Restrict VPN implied rules NOW. If patching cannot happen immediately, disable VPN implied rules in SmartConsole and create explicit rules limiting Site-to-Site VPN (UDP/500 and UDP/4500) to specific, known peer IP addresses only.
- Isolate your Management Server. It should not have a route from any untrusted network. Apply host-based firewall rules to restrict the management web service to administrator source IPs only.
- Hunt for compromise. Check IKE negotiation logs for certificates with CN=vpn or CN=vpn-user from unknown peers. Review Management Server access logs for anomalous file upload or traversal patterns from July 23 onwards.
- Audit end-of-support gateways. If you are still running R80 or R81 (pre-R81.10), Check Point cannot provide a LivePatch. The only safe option is to upgrade to a supported release or take the appliance offline until you can.
For a broader view of how firewall policy hygiene and auditing should underpin your response process, see our guide on Firewall Policy Audits in India — the discipline that catches dangerous implied rules before attackers do.
Frequently Asked Questions
Does this vulnerability affect Check Point CloudGuard or Harmony products?
Based on current advisories, CVE-2026-85102 and CVE-2026-93616 affect the on-premises Security Gateway and Management Server product lines, including Spark Firewall appliances. CloudGuard Network Security (cloud-delivered) operates on a different codebase — check the Check Point SecureKnowledge portal directly for CloudGuard-specific guidance, as cloud-managed versions may have received silent updates. Do not assume you are safe without verifying your specific SKU and version.
My gateway is behind NAT and not directly internet-exposed. Am I safe?
Partially. CVE-2026-85102 requires that the attacker can reach the VPN endpoint (UDP/500, UDP/4500, or TCP/443 for SSL-VPN). If your gateway VPN ports are fully firewalled from the internet, the gateway RCE risk is lower — but you must still patch CVE-2026-93616 on the Management Server. More importantly, Site-to-Site VPN by definition exposes these ports to peer gateways; if any peer is compromised, the attack chain remains viable.
We applied LivePatch Take 28 last week. Are we fully protected?
No. This is a critical point from the official advisory: LivePatch Take 28/29 addresses CVE-2026-85102 on the gateway, but does NOT cover CVE-2026-93616 on the Management Server. You need to apply the management-side fix separately. Verify both by checking the installed take number on both the gateway and the Management Server independently.
What are the indicators of compromise (IoCs) we should hunt for?
Check Point has identified certificates with subjects including CN=vpn and CN=vpn-user variants in exploitation traffic. On the management side, look for anomalous HTTP requests to management web service paths containing traversal sequences (../ or URL-encoded equivalents) from unexpected source IPs. Establish a baseline of July 22 and work forward — exploitation of CVE-2026-93616 predates the public disclosure by nearly two months.
The Bottom Line: Perimeter Devices Are High-Value Targets
This incident reinforces a pattern that security teams in India and globally need to internalise: perimeter security devices are among the most valuable initial-access targets for sophisticated threat actors, precisely because they sit outside endpoint-protection and EDR coverage. A compromised firewall or VPN gateway is invisible to most traditional security tooling — it does not generate Windows event logs, it is not covered by your antivirus, and its operational normalcy is almost never questioned.
This is why zero-trust architecture and continuous verification matter so much. A zero-trust model does not treat a valid VPN session as inherently trusted — every connection is verified against identity, device posture, and behaviour at every step. When a gateway is compromised, zero-trust controls limit the blast radius. When the gateway is your only control plane, everything downstream is at risk.
Sources for this analysis: BleepingComputer, Rescana Advisory, nFlo Knowledge Base, ThreatAft, and the CISA KEV Catalog.
Is Your Firewall Estate Fully Patched and Audited?
With 30 years of hands-on experience across enterprise networks in Delhi NCR and beyond, Sanjay Seth and the P J Networks team can perform a rapid vulnerability assessment of your perimeter devices — including patch verification, management-plane exposure review, and zero-trust readiness gap analysis.