Check Point Warns of Active Exploitation of Security Gateway VPN Flaw
Cybersecurity company Check Point has confirmed active exploitation of a pre-authentication remote code execution vulnerability impacting its Security Gateway product.

Active Exploitation of Security Gateway RCE Flaw
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution vulnerability located in the VPN certificate-handling functionality of its Security Gateway product. Detailed insights on the ongoing attacks were shared as the company outlined the scope of the threat in an official advisory that reads Check Point’s alert.
The same advisory additionally warns of threat actors exploiting a pre-authentication path traversal flaw tracked as CVE-2026-93616. This separate vulnerability impacts the Management web service and can allow script execution as well as Java class loading. Check Point stated that CVE-2026-93616 has been actively exploited as a zero-day since July 23.
Timeline and Attack Attribution Observations
Earlier in the month, the Dutch Nationaal Cyber Security Centrum (NCSC) alerted of the Security Gateway issue and urged users to apply available security updates promptly as imminent exploitation was expected. Following those warnings, Check Point confirmed that malicious activity officially commenced on September 12, with attackers leveraging VPNs and proxies to obscure their physical locations.
According to the company, a wave of exploitation attempts targeted Spark customers starting September 12, 2026. The security vendor noted that these attempts originated from anonymization infrastructure, including various VPN services and proxies. While specific certificate subjects were observed during these incidents, the company highlighted that those subjects reflect only current observations and additional ones may also be in active use.
CISA Response and Federal Mandates
In response to the active threats, the Cybersecurity and Infrastructure Security Agency added both vulnerabilities to its Known Exploited Vulnerabilities catalog. The inclusion urges federal agencies to apply all available fixes and mitigations by September 25, 2026, to protect critical infrastructure from potential compromise.
Recommended Software Updates and Patches
Check Point’s advisory on CVE-2026-85102 strongly recommends that administrators install Check Point LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways. Alternatively, teams can install a fixed Jumbo Hotfix such as R81.20 Take 166, R82 Take 126, R82.10 Take 44, R81.10 Take 190, or later releases.
Furthermore, customers are instructed to update Spark firewalls to version R82.00.10 Build 2325, R81.10.17 Build 4968, or subsequent iterations. System administrators can verify whether LivePatch is active by executing the cpinfo -y CPupdates command on the Security Gateway while operating in expert mode. The advisory also cautions that customers who installed an earlier offline LivePatch package specifically require Take 26 to achieve full vulnerability coverage.
Alternative Mitigations and Management Service Guidance
If updating the system is not immediately feasible, Check Point advises disabling VPN implied rules and establishing explicit rules that restrict Site-to-Site VPN traffic on UDP/500 and UDP/4500 exclusively to specified peer IP addresses. For Remote Access VPN configurations, administrators should allow only necessary services over UDP/500, UDP/4500, TCP/443, and TCP/80 where applicable, while restricting source client IP ranges whenever possible. The company notes that these specific mitigation steps do not apply to locally managed Spark firewalls.
Sources
- BleepingComputerCheck Point warns of hackers exploiting Security Gateway VPN RCE flaw