Your firewall and its management plane just got the same three-day federal clock. CISA added two Check Point flaws to KEV on September 22 with a September 25 due date — one is a pre-auth VPN gateway RCE already sprayed at Spark customers; the other is a brand-new management web-service zero-day.
What happened
CVE-2026-85102 is improper certificate validation during VPN negotiation on Check Point Security Gateway and Spark Firewall (Site-to-Site or Remote Access VPN). An unauthenticated remote attacker can reach arbitrary code execution on the gateway. Check Point disclosed and shipped fixes on September 9; as of September 22 they report active exploitation attempts against Spark customers worldwide, with suspicious cert subjects like CN=vpn,OU=users,O=global.
CVE-2026-93616 is a pre-authentication path traversal in the Security Management web service: upload/execute an arbitrary script and load an arbitrary Java class. Check Point calls it a newly discovered zero-day with limited, pinpointed exploitation (observed as early as July 23). LivePatch Take 28/29 does not fix it — you need the Jumbo takes in sk1000171.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
CISA added both to KEV on September 22, 2026. Federal due date: September 25, 2026. Forensic triage required under BOD 26-04 for both.
Why it matters
Gateway RCE on the VPN path is the front door — Mobile Access follow-on often looks like internal port and service scans from a “logged-in” user. Management-plane RCE is the master key: policy, logs, and every managed gateway sit behind it. Two CVSS 9.8s, both unauth, both KEV, both due Friday.
If you applied LivePatch and stopped there for management, you are not done. Jumbo Hotfix takes are the actual fix for the management bug.
What to do first
- Inventory every Security Gateway / Spark with Site-to-Site or Remote Access VPN and every Security Management / MDS / Log / SmartEvent server.
- Apply sk1000117 builds for CVE-2026-85102 immediately if not already on the September 9 fix.
- Apply sk1000171 Jumbo takes for CVE-2026-93616 — do not rely on LivePatch Take 28/29.
- Hunt Mobile Access / certificate-based logins for anomalous subjects and second-stage internal scanning from those sessions.
- Forensic triage per BOD 26-04: preserve management and gateway logs, unexpected admin objects, script drops, and pre-patch window access before you wipe evidence with the upgrade.
- If compromise is likely: isolate, rebuild from known-good, rotate credentials/certs/SIC, and re-push policy from a trusted management instance.
Details
- CVEs: CVE-2026-85102 (gateway VPN cert validation RCE, CVSS 9.8); CVE-2026-93616 (management path traversal → script/Java class load, CVSS 9.8)
- Products: Security Gateway, Spark Firewall; Security Management / MDS / Log Server / SmartEvent
- KEV: Added 2026-09-22; federal due 2026-09-25; forensic triage Yes
- Advisories: sk1000117, sk1000171
- Ransomware use (CISA): Unknown
Hunt / verify
- Confirm installed Jumbo / hotfix takes match sk1000117 and sk1000171 — not “updates applied.”
- Search Mobile Access logs for anomalous certificate subjects (including but not limited to CN=vpn / vpn-user / vpnuser patterns).
- Review management web-service logs for unexpected uploads, path traversal patterns, and Java class loads around July 23 and the pre-patch window.
- Diff management objects and gateway configs against last known-good.
Sources
- https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
- https://support.checkpoint.com/results/sk/sk1000117
- https://support.checkpoint.com/results/sk/sk1000171
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-85102
- https://nvd.nist.gov/vuln/detail/CVE-2026-93616
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.