Vulnerabilities

Check Point Management Zero-Day Exploited as VPN Attacks Target Spark Firewalls

Check Point customers who installed the 9 September hotfixes closed the VPN flaw attackers began probing three days later. Management servers running those same builds are still exposed to a second flaw, CVE-2026-93616 which Check Point disclosed on 22 September and says was exploited as a zero-day in July.

Both flaws carry a CVSS score of 9.8 and need no credentials. CISA added them to its Known Exploited Vulnerabilities catalogue and gave US federal agencies until 25 September to fix them.

Take 44 Fixed the VPN Flaw. It Is Also the Last Vulnerable Build.

The overlap sits in Check Point’s own tables. For CVE-2026-85102, the certificate-handling flaw in the Security Gateway VPN, the fixed Jumbo Hotfix levels are R82.10 Take 44, R82 Take 126, R81.20 Take 166 and R81.10 Take 190. For CVE-2026-93616, Check Point lists exactly those takes and anything lower as affected on Security Management.

LivePatch does not close the gap either. Check Point states that LivePatch Take 28 and 29 do not address the management flaw. R82.20 which the VPN bug never touched, is on the affected list.

The fix is a separate hotfix documented in sk1000171. Raise it as its own change not as a follow-on to the September update.

A Handful of Attacks on 23 July

Check Point says it observed a handful of pinpointed attacks exploiting CVE-2026-93616 on 23 July 2026. The flaw is a pre-authentication path traversal in the management web service. It lets an attacker run a script from an arbitrary path and load an arbitrary Java class.

The vendor’s wording is narrower, a few targeted attacks on a single date. Check Point has not said who carried them out, how many customers were hit or what the attackers reached.

That silence matters more than the date. A management zero-day used sparingly, two months before any fix existed is not something to close with a hotfix and forget. Treat every Security Management server that was reachable from the internet in July as a possible compromise until the indicators in sk1000171 say otherwise.

Three Days From Fix to Exploitation Attempts

The VPN flaw moved faster. Check Point released fixes for CVE-2026-85102 on 9 September with no evidence of exploitation. The Dutch Nationaal Cyber Security Centrum warned the next day that attacks were imminent and CERT-EU urged organisations to apply the hotfixes immediately.

From 12 September, Check Point saw a wave of exploitation attempts against Spark customers routed through VPN services and proxies. The certificates observed so far carried three subjects:

  • CN=vpn,OU=users,O=global
  • CN=vpn-user,OU=users,O=global
  • CN=vpnuser,OU=users,O=global

Check Point writes that customers who applied the fix “are already protected”. That holds from the moment of patching. It says nothing about a Spark unit left unpatched over the weekend of 12 September and the advisory describes attempts without saying how many succeeded.

Four Exploited Check Point Flaws Since June

This advisory is not an isolated one. In June, CISA listed CVE-2026-50751 an IKEv1 authentication bypass in Check Point VPN, Mobile Access and Spark that Check Point said had been exploited since May. One incident was linked with medium confidence to a Qilin ransomware affiliate according to Security Affairs.

In July came CVE-2026-16232, an authentication bypass in Security Management and Multi-Domain Management that gives unauthenticated attackers full administrative access. Security Affairs reported it as actively exploited.

Two of the four sit in the management plane, the console that pushes policy to every gateway it controls. Eclypsium’s InfraTrust Pulse found the highest-value exploited infrastructure flaws were in administrative software for the second month running.

Mobile Access Logins Are Where to Start

Check Point’s hunting advice for the VPN flaw is specific. Review logs for anomalous certificate-based Mobile Access logins and do not limit the search to the three subjects above. Look for second-stage activity from those sessions, the follow-up often involves internal port and service scans.

Where a gateway cannot be patched today, BleepingComputer’s summary of the advisory lists a stopgap, disable the implied VPN rules and restrict Site-to-Site VPN on UDP 500 and 4500 to known peer addresses. It does not apply to locally managed Spark firewalls.

For the management flaw, the indicators and hunting steps are in sk1000171. Install the hotfix, then search back to 23 July.

References

  1. Security Advisory: Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616
  2. Check Point Support Article sk1000171
  3. Check Point Warns of Hackers Exploiting Security Gateway VPN RCE Flaw
  4. Dutch NCSC: Critical Check Point VPN Flaws Exploitation is Imminent
  5. Critical Vulnerabilities in Check Point Products
  6. Known Exploited Vulnerabilities Catalog
  7. U.S. CISA Adds BerriAI LiteLLM and Check Point Security Gateway Flaws to its Known Exploited Vulnerabilities Catalog

This post is also available in: Svenska

Erik Berg

Erik Berg is CTO and Principal Security Architect at eBuilder Security, with more than a decade in blue team security operations across the private and public sectors, and a focus on emerging threats including the security risks that come with AI.