Check Point VPN and Management Server Both Hit by Pre-Auth RCE
Check Point disclosed and patched two pre-authentication remote code execution vulnerabilities in its Security Gateway and Security Management products this month. Both carry a CVSS score of 9.8. Both are confirmed as actively exploited in the wild. The CISA deadline for federal agencies passed September 25, and exploitation attempts against non-federal organizations are still ongoing.
CVE-2026-85102: code execution through VPN certificate handling
CVE-2026-85102 lives in the gateway's VPN certificate-handling routine. During IKE negotiation (the handshake that establishes a VPN tunnel), the gateway fails to properly validate certificate trust before proceeding. An attacker sends a crafted certificate before authentication completes, and the gateway accepts and processes it in a way that yields code execution on the appliance itself. It requires no credentials and no VPN account, only a crafted packet.
Check Point shipped the fix on September 9 via Jumbo Hotfix (R82 Take 126 or later) and also pushed it through its LivePatch mechanism (Take 24) with automatic rollout to connected gateways. Three days later, on September 12, exploitation attempts were already hitting Check Point Spark customers globally, originating from anonymization infrastructure: VPN exit nodes and proxy services designed to obscure the attacker's true origin.
Affected versions span the last several major release trains: R81, R81.10.x, R81.20, R82, R82.00.x, and R82.10, plus both centrally managed and locally managed Spark Firewalls. R82.20 is not affected.
CVE-2026-93616: path traversal in Security Management
The second vulnerability is in a different product and arguably carries worse consequences. CVE-2026-93616 is a pre-authentication path traversal flaw in Check Point's Security Management web service. An unauthenticated attacker with network access to the management service can escape directory restrictions, place arbitrary files on the server, then execute a script or load an arbitrary Java class, again with no login required.
Check Point confirmed a small number of highly targeted attacks dating back to July 23, 2026, nearly two full months before a patch shipped on September 22. CISA added CVE-2026-93616 to its Known Exploited Vulnerabilities catalog the same day the fix dropped. Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
Chaining the two flaws
Each vulnerability is independently severe. Together, they describe a clean path to owning the entire security stack. Compromise the gateway via CVE-2026-85102 to gain a foothold inside the network, then pivot to the management server via CVE-2026-93616 to rewrite firewall policy, add your own access rules, and cover your tracks in the logs. Or, if the management server is reachable directly from the internet (which it shouldn't be, but sometimes is), skip straight to step two.
Management server compromise is particularly damaging because it doesn't give you one box; it gives you control over the rules every downstream protected device follows. An attacker who owns the management server can modify which traffic is permitted, which VPN users exist, and what gets logged to SIEM. The forensic trail can be altered before you know to look.
Who is exposed
CVE-2026-85102 affects any Check Point deployment with Site-to-Site or Remote Access VPN enabled, which covers the majority of production deployments. CVE-2026-93616 is relevant wherever the management web service is accessible, whether on a standalone management server or co-located with the gateway.
Small and mid-size businesses running Check Point appliances for branch-office VPN or remote-access infrastructure, particularly those not on an aggressive hotfix cadence, are most likely to still be running unpatched versions. If your management server has any public or semi-public network reachability, treat CVE-2026-93616 as an emergency regardless of when you last reviewed your patch level.
Patching and mitigation steps
For CVE-2026-85102 (Security Gateway):
- Apply Jumbo Hotfix R82 Take 126 or later. Verify LivePatch Take 24 is installed on connected gateways.
- For R81.20 and older supported branches, apply the corresponding hotfix from Check Point's support portal via CPUSE or SmartUpdate.
- If immediate patching is not possible: disable VPN implied rules and restrict Site-to-Site VPN traffic to known peer IP addresses on
UDP/500andUDP/4500via explicit allow rules.
For CVE-2026-93616 (Security Management):
- Apply the September 22 hotfix for your management version.
- Restrict network access to the management web service to trusted administrator source IPs at the firewall or ACL level.
- Treat any management server that ran unpatched before September 22 as potentially compromised: audit administrator accounts, review policy changes since July 23, and look for unexpected Java processes or newly created service accounts.
Checking for compromise after patching
Check Point's own advisory notes that patching does not discharge the obligation to verify no prior intrusion occurred. For CVE-2026-93616, exploitation was underway for months before defenders had a fix to apply. Pull management audit logs for unexpected policy changes, review VPN user lists for accounts you didn't create, and check gateway logs for session initiations from anonymized infrastructure.
If you cannot confidently account for management server activity since July 23, a rebuild from a verified clean backup is worth the downtime. That's why tested restores aren't optional. At Falcon Internet, we've run restore drills long enough to know that the backup you never tested is the one that fails when it matters most.