Cybersecurity

Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Photo: Avishai Teicher, Wikimedia Commons, CC BY-SA 4.0
0 0
XWhatsAppTelegramLinkedIn

Check Point published a security advisory on September 22, 2026 confirming that attackers are actively exploiting two vulnerabilities in its firewall and management products, both rated 9.8 out of 10 on the CVSS severity scale and both usable without any login.

The first, CVE-2026-85102, is a pre-authentication remote code execution flaw in the way Security Gateway validates certificate data during VPN negotiation. Check Point disclosed it and shipped fixes on September 9, and says it had no evidence of exploitation at that point. That changed three days later. "Starting September 12, 2026, we observed a wave of exploitation attempts against Spark customers," the company wrote, adding that the attempts came from anonymization infrastructure including VPN services and proxies. The attackers used client certificates with subjects such as CN=vpn, CN=vpn-user and CN=vpnuser, all under OU=users, O=global — a list Check Point explicitly describes as incomplete.

The second flaw, CVE-2026-93616, is a pre-authentication path traversal in the Check Point Management web service that lets an attacker run a script from an arbitrary path and load an arbitrary Java class. Check Point treats it as a zero-day: the fix arrived with the September 22 advisory, but the company says it saw "a handful of pinpointed" attacks as far back as July 23, 2026. The advisory also warns that LivePatch Take 28/29 does not cover this one.

The timing is what makes this urgent. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 22 and set a remediation due date of September 25, 2026 for US federal agencies under Binding Operational Directive 26-04, flagging both entries as requiring forensic triage. That is a three-day window, and the same patches are what everyone else running the gear needs.

For CVE-2026-85102, Check Point's advisory recommends LivePatch Take 26 on supported R81.20, R82 or R82.10 gateways, or a fixed Jumbo Hotfix — R81.20 Take 166, R82 Take 126, R82.10 Take 44 or R81.10 Take 190, or later. Spark firewalls should move to R82.00.10 Build 2325 or R81.10.17 Build 4968 or later. Administrators can check whether LivePatch is active by running cpinfo -y CPupdates in expert mode. Where patching is not immediately possible, Check Point advises disabling the VPN implied rules and writing explicit rules that limit Site-to-Site VPN on UDP/500 and UDP/4500 to specific peer IP addresses; those mitigations do not apply to locally managed Spark firewalls. Hunting guidance and indicators for the management flaw are in support article sk1000171.

Two things are still unknown. Check Point has not published how many organizations were actually compromised in either campaign, and it has not said whether the two sets of attacks are connected. Warning signs were already visible before the advisory: BleepingComputer notes the Dutch national cyber security centre NCSC flagged the Security Gateway issue on September 10 and urged customers to patch, expecting exploitation to follow.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.