Check Point CVE-2026-85102 / 93616: VPN Gateway RCE + Management Zero-Day — KEV Due September 25

By George Bailey   Published: 09/22/26   Updated: 09/22/26   3 min read

Your firewall and its management plane just got the same three-day federal clock. CISA added two Check Point flaws to KEV on September 22 with a September 25 due date — one is a pre-auth VPN gateway RCE already sprayed at Spark customers; the other is a brand-new management web-service zero-day.

What happened

CVE-2026-85102 is improper certificate validation during VPN negotiation on Check Point Security Gateway and Spark Firewall (Site-to-Site or Remote Access VPN). An unauthenticated remote attacker can reach arbitrary code execution on the gateway. Check Point disclosed and shipped fixes on September 9; as of September 22 they report active exploitation attempts against Spark customers worldwide, with suspicious cert subjects like CN=vpn,OU=users,O=global.

CVE-2026-93616 is a pre-authentication path traversal in the Security Management web service: upload/execute an arbitrary script and load an arbitrary Java class. Check Point calls it a newly discovered zero-day with limited, pinpointed exploitation (observed as early as July 23). LivePatch Take 28/29 does not fix it — you need the Jumbo takes in sk1000171.

CISA added both to KEV on September 22, 2026. Federal due date: September 25, 2026. Forensic triage required under BOD 26-04 for both.

Why it matters

Gateway RCE on the VPN path is the front door — Mobile Access follow-on often looks like internal port and service scans from a “logged-in” user. Management-plane RCE is the master key: policy, logs, and every managed gateway sit behind it. Two CVSS 9.8s, both unauth, both KEV, both due Friday.

If you applied LivePatch and stopped there for management, you are not done. Jumbo Hotfix takes are the actual fix for the management bug.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.