Check Point CVE-2026-93616 and CVE-2026-85102 Exploited: Patch Now

A management-server zero-day used since July and a VPN bug now hitting Spark firewalls: here are the fixed Jumbo Hotfix takes, the log checks and the September 25 CISA deadline.

Check Point network security artwork showing a glass office building lit in pink and red against a dark background with faint lines of code
Check Point network security artwork. Image: Check Point.

Check Point is urging customers to patch two critical, actively exploited vulnerabilities right away. CVE-2026-93616 is a zero-day in Check Point’s Security Management server that lets an unauthenticated attacker upload and run scripts, and it was fixed on September 22, 2026. CVE-2026-85102 is a remote code execution flaw in Security Gateway and Spark firewall VPN certificate handling; it was patched on September 9 and attackers began exploiting it on September 12. Both are rated CVSS 9.8, and CISA added both to its Known Exploited Vulnerabilities catalog on September 22 with a remediation deadline of September 25.

Key facts

  • CVE-2026-93616: pre-authentication path traversal and file upload in the Check Point Management web service. CVSS 9.8. Exploited as a zero-day in a handful of targeted attacks first seen on July 23, 2026.
  • CVE-2026-85102: improper certificate validation during VPN negotiation on Security Gateway and Spark firewalls. CVSS 9.8. Fixed September 9, exploited against Spark customers since September 12.
  • Management fix: R82.20 Security Hotfix, or Jumbo Hotfix Accumulator R82.10 Take 45, R82 Take 127, R81.20 Take 170, R81.10 Take 192.
  • Gateway fix: LivePatch Take 26, or Jumbo Hotfix R82.10 Take 44, R82 Take 126, R81.20 Take 166, R81.10 Take 190. Spark builds R82.00.10 Build 2325 and R81.10.17 Build 4968.
  • CISA KEV: both added September 22, 2026. Federal deadline: September 25, 2026.

What happened

On September 22, Check Point published a security advisory on its corporate blog, signed by Lotem Finkelstein, VP Research. It covers two separate problems that attackers are now using at the same time. The first is a vulnerability Check Point had already fixed. The second is a zero-day that Check Point Research found being used in a small number of targeted attacks.

According to the Check Point security advisory on active exploitation, the gateway bug CVE-2026-85102 was disclosed and fixed on September 9, 2026, when the company says it had no evidence of exploitation. It is now seeing exploitation attempts against Check Point Spark customers around the world. The management-server bug CVE-2026-93616 is new, and the fix came out with the advisory.

“CVE-2026-93616 is a newly discovered zero-day vulnerability in Security Management”
Lotem Finkelstein, VP Research, Check Point Software

The two bugs hit different parts of a Check Point deployment. CVE-2026-85102 affects the gateways that terminate VPN traffic at the network edge. CVE-2026-93616 affects the management and logging servers that hold policy for the entire estate. An organization running both, which describes most Check Point customers, has to patch in two places.

CVE-2026-93616: the Security Management zero-day

Check Point’s support article sk1000171 for CVE-2026-93616 describes a directory traversal and file upload vulnerability that lets an unauthenticated attacker upload and execute arbitrary scripts on the Management Server. The blog adds that the flaw lives in the Check Point Management web service and lets an attacker run a script from an arbitrary path and load an arbitrary Java class. No login is required.

The vendor says the bug has been “exploited in the wild” and that it knows of a handful of customers who were attacked. It dates the observed attacks to July 23, 2026, which means the flaw was used as a zero-day for about two months before a patch existed.

Which products are affected

  • Security Management Server
  • Multi-Domain Security Management Server
  • Log Server and Multi-Domain Log Server
  • SmartEvent

Check Point lists Smart-1 Cloud (where the fix has already been applied), Check Point firewall appliances and Check Point Spark firewalls as not affected by this CVE.

Affected and fixed versions

VersionVulnerableFixed in
R82.20Yes (all builds before the hotfix)R82.20 Security Hotfix
R82.10Jumbo Hotfix Take 44 or lowerJumbo Hotfix Accumulator Take 45 and later
R82Jumbo Hotfix Take 126 or lowerJumbo Hotfix Accumulator Take 127 and later
R81.20Jumbo Hotfix Take 166 or lowerJumbo Hotfix Accumulator Take 170 and later
R81.10 (end of support)Jumbo Hotfix Take 190 or lowerJumbo Hotfix Accumulator Take 192 and later
R80, R80.10, R80.20, R80.30, R80.40, R81 (end of support)YesNo fix listed; upgrade to a supported version

Two details matter here. First, Check Point says LivePatch Take 28/29 does not address this issue, and because of the nature of the fix, no LivePatch will be released for it. Customers who rely on LivePatch for fast gateway fixes have to install a Jumbo Hotfix or the R82.20 hotfix on their management servers. Second, the new Jumbo Hotfix takes also include the fix for CVE-2026-91843 (sk1000155). The NVD entry for CVE-2026-91843 describes it as a stack overflow in the unauthenticated login process that may allow remote code execution with root privileges, also rated CVSS 9.8.

CVE-2026-85102: the VPN certificate flaw now hitting Spark firewalls

The gateway bug is tracked in Check Point sk1000117. Improper validation of certificate data during VPN negotiation may let an unauthenticated remote attacker execute arbitrary code on the Security Gateway. The CVSS score is 9.8.

Exposure depends on how the VPN is set up:

  • Remote Access VPN on an affected Security Gateway or Spark firewall is in scope.
  • Site-to-Site VPN is affected only when the gateway uses or allows certificate-based authentication. Check Point notes that VPN communities containing Dynamic IP (DAIP) gateways or Large Scale VPN (LSV) gateways enable certificate authentication.
  • Gateways that only take part in encryption communities using a pre-shared key are not vulnerable.

Affected versions are R81.20, R82 and R82.10, plus the end-of-support R80 through R81.10 releases and Spark firmware lines R81.10.x and R82.00.x. R82.20 is listed as not affected.

In a September 20 update to the article, Check Point says the vulnerability is actively exploited on Spark firewalls as of September 12, 2026. The blog adds that the attempts came from anonymization infrastructure, including VPN services and proxies.

How to patch the gateways

PlatformFix option
R82.10, R82, R81.20 gatewaysLivePatch Take 26 (automatic, or offline package BUNDLE_URGENT_SECURITY_UPDATE_…_AUTOUPDATE Take 26)
R82.10Jumbo Hotfix Accumulator Take 44 and later
R82Jumbo Hotfix Accumulator Take 126 and later
R81.20Jumbo Hotfix Accumulator Take 166 and later
R81.10Jumbo Hotfix Accumulator Take 190 and later
Spark R82.00.xR82.00.10 Build 2325 and later
Spark R81.10.xR81.10.17 Build 4968 and later

If you already installed the offline LivePatch package earlier in September, check your Jumbo Hotfix level. A September 14 update says customers on R82.10 Take 24 or lower, R82 Take 107 or lower, or R81.20 Take 146 or lower must install LivePatch Take 26, because Check Point found a rare scenario where the earlier package does not fully cover the CVE.

To confirm the patch is active, Check Point says to run cpinfo -y CPupdates in Expert mode and look for the Take 26 bundle. On a gateway or ClusterXL member, cplp list should list the cpcert, iked, vpn, vpnrad and cprid components against both CVE-2026-85102 and CVE-2026-85103. On a Scalable Platform Security Group, run g_all cplp list. According to NVD, CVE-2026-85103 is a companion heap-based buffer overflow in VPN certificate ASN.1 decoding, also rated 9.8, and the same LivePatch fixes it.

How to tell if you are affected

Start with inventory. Every Security Management, Multi-Domain, Log, Multi-Domain Log and SmartEvent server below the fixed takes is exposed to CVE-2026-93616, and the risk is highest when the management web service can be reached from untrusted networks. Every gateway or Spark appliance running Remote Access VPN, or Site-to-Site VPN with certificate authentication, below the fixed versions is exposed to CVE-2026-85102.

Check Point has not published a count of affected customers beyond “a handful” for the management zero-day, and it describes the Spark activity as global.

Indicators of compromise and how to hunt

Management servers (CVE-2026-93616)

Check Point gives two checks to run from Expert mode on every management and log server:

  1. Search the cpm.elg logs in $MDS_FWDIR/log/ for SmartConsole login requests with a username longer than 1,000 characters. If you find any, check /var/log/dump/usermode/ for an FWM or MDS core dump created at the same time. A matching core dump points to a possible exploitation attempt.
  2. Search the same logs for ERROR entries from upgrade.base.ReflectionUtils reading “Failed to load allResourceFiles map from”. Any file path in that output containing directory traversal sequences such as ../ may indicate an attempt to exploit the bug.

The exact grep commands are in sk1000171. Treat a hit as a reason to start incident response, not just to patch. Patching closes the hole but does not remove anything an attacker already placed on the server.

Gateways and Spark (CVE-2026-85102)

In SmartConsole or Spark Management, open Logs & Monitor (or Logs & Events) and search for certificate-based Mobile Access logins after September 12, 2026, using the query product: "Mobile Access" AND action: "Log In" AND "Certificate". Look for unrecognized users, clients or source IP addresses. Check Point lists three certificate subjects seen so far, and it warns that the list is not exhaustive:

  • CN=vpn,OU=users,O=global
  • CN=vpn-user,OU=users,O=global
  • CN=vpnuser,OU=users,O=global

If a login is unauthorized, the company says to look for follow-on activity from that user, such as scans of internal ports and services.

Mitigations if you cannot patch today

For the management zero-day, Check Point’s advice is to put Management Servers behind a Security Gateway, following its Gateway and Management Hardening guide. Make sure TCP port 19009 can only be reached from trusted IP addresses. If a gateway with implied rules already protects the server, restrict Trusted Clients to trusted internal addresses. In SmartConsole, that setting is under Manage & Settings > Permissions & Administrators > Trusted Clients. Restricting Trusted Clients creates an implied rule that limits access.

For the VPN flaw, Check Point describes a workaround for systems that cannot take a Jumbo Hotfix or LivePatch, and warns that a mistake can break connectivity:

  • Site-to-Site VPN: disable the VPN implied rules and manually allow UDP/500 and UDP/4500 only from specific peer IP addresses (see sk179346).
  • Remote Access VPN: disable the Remote Access implied rules and create explicit access rules for UDP/500 (IKE), UDP/4500 (NAT-T), TCP/443 and, where needed, TCP/80, limited to your clients’ source ranges if possible.

These workarounds are not available on locally managed Spark firewalls, and that is where exploitation is happening. For those appliances, updating to the fixed firmware builds is the only listed fix.

CISA KEV listing and the September 25 deadline

CISA added both CVEs to the Known Exploited Vulnerabilities catalog on September 22, 2026, with a due date of September 25, 2026. An exploited F5 BIG-IP APM flaw was added to the catalog on the same date, with the same deadline. The catalog entries tell agencies to apply vendor mitigations under Binding Operational Directive 26-04, which sets patch timelines based on asset exposure, KEV status, whether exploitation can be automated, and the technical impact. Both entries are also flagged for CISA’s forensic triage requirements. Agencies are told to follow BOD 26-04 guidance or stop using the product if no mitigation is available. The directive only binds federal civilian agencies, but the three-day window shows how urgently CISA rates these flaws.

Timeline

Date (2026)Event
July 23Check Point Research observes targeted exploitation of what becomes CVE-2026-93616
September 9CVE-2026-85102 disclosed and fixed; no exploitation known at the time
September 12Exploitation of CVE-2026-85102 against Spark firewalls begins
September 14sk1000117 updated: some offline LivePatch users must install LivePatch Take 26
September 20sk1000117 updated to confirm active exploitation on Spark
September 22Check Point publishes the joint advisory and the CVE-2026-93616 fix; CISA adds both CVEs to KEV
September 25CISA remediation deadline for federal civilian agencies

What to do now

  1. List every Check Point management, log and SmartEvent server, and every gateway and Spark appliance, with its version and Jumbo Hotfix take.
  2. Patch management servers to the R82.20 Security Hotfix or the fixed Jumbo Hotfix takes. Do not count on LivePatch for CVE-2026-93616.
  3. Patch gateways with LivePatch Take 26 or the fixed Jumbo Hotfix takes, and update Spark firmware to the fixed builds. Verify with cplp list.
  4. Restrict access to the management web service and TCP/19009 to trusted addresses, whatever your patch status.
  5. Run the log checks above and review certificate-based Mobile Access logins since September 12.
  6. If anything looks suspicious, escalate to incident response and contact Check Point Support.

The bottom line: this is a two-front problem. The VPN bug has had a public fix for two weeks and is now being exploited against Spark customers worldwide. The management zero-day has been used quietly against select targets since July. Patch both, and check your logs even if you patched promptly.

Frequently asked questions

What is CVE-2026-93616?

CVE-2026-93616 is a pre-authentication path traversal and file upload vulnerability in the Check Point Management web service. It lets an unauthenticated attacker upload and execute arbitrary scripts on Security Management, Multi-Domain, Log and SmartEvent servers, and it carries a CVSS score of 9.8.

Is CVE-2026-93616 being exploited?

Yes. Check Point says it observed a handful of targeted attacks on July 23, 2026, before a fix existed, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 22, 2026.

Which Jumbo Hotfix fixes CVE-2026-93616?

The fix is in the R82.20 Security Hotfix and in Jumbo Hotfix Accumulator R82.10 Take 45, R82 Take 127, R81.20 Take 170 and R81.10 Take 192 or later. Check Point says no LivePatch will be released for this issue.

Does LivePatch fix CVE-2026-85102?

Yes. LivePatch Take 26 fixes CVE-2026-85102 on R82.10, R82 and R81.20 gateways. You can verify it by running cplp list in Expert mode, which should show CVE-2026-85102 and CVE-2026-85103 against the VPN components.

Is Check Point R82.20 affected by the VPN flaw?

No. Check Point lists R82.20 as not affected by CVE-2026-85102. R82.20 management servers do still need the R82.20 Security Hotfix for CVE-2026-93616.

What is the CISA deadline for these Check Point flaws?

CISA set September 25, 2026 as the remediation due date for both CVE-2026-93616 and CVE-2026-85102 for federal civilian agencies under BOD 26-04.

Sources

More on Check Point →Check PointCVE-2026-93616CVE-2026-85102Zero-dayCISA KEVVPN security
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all