{"id":994,"date":"2026-09-26T23:37:35","date_gmt":"2026-09-26T23:37:35","guid":{"rendered":"https:\/\/seoscanpro.ai\/blog\/check-point-security-gateway-vpn-rce-flaw\/"},"modified":"2026-09-26T23:37:36","modified_gmt":"2026-09-26T23:37:36","slug":"check-point-security-gateway-vpn-rce-flaw","status":"publish","type":"post","link":"https:\/\/seoscanpro.ai\/blog\/check-point-security-gateway-vpn-rce-flaw\/","title":{"rendered":"Check Point confirms active exploitation of Security Gateway VPN RCE flaw"},"content":{"rendered":"<p>Check Point has confirmed that two pre-authentication flaws in its Security Gateway product are under active exploitation, giving administrators of supported gateways a clear path to patch and a fallback set of firewall rules when patching is not yet possible.<\/p>\n<h2>What Check Point disclosed<\/h2>\n<p>The cybersecurity company confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. The same advisory also covers a second pre-authentication flaw, CVE-2026-93616, a path traversal issue in the Management web service that can permit script execution and Java class loading.<\/p>\n<p>CVE-2026-93616 has been exploited as a zero-day since July 23, 2026. For CVE-2026-85102, Check Point reported that malicious activity began on September 12, 2026, with attackers routing traffic through VPNs and proxies to obscure their origin.<\/p>\n<p>The advisory lists three certificate subjects seen during the September 12 wave of attempts against Spark customers:<\/p>\n<ul>\n<li>CN=vpn,OU=users,O=global<\/li>\n<li>CN=vpn-user,OU=users,O=global<\/li>\n<li>CN=vpnuser,OU=users,O=global<\/li>\n<\/ul>\n<p>Check Point noted that these subjects reflect current observations and that additional variants may be in use.<\/p>\n<h2>How the warning reached defenders<\/h2>\n<p>On September 10, 2026, the Dutch Nationaal Cyber Security Centrum (NCSC) alerted organizations to the Security Gateway issue and warned that imminent exploitation was expected. The Dutch alert preceded the on-network activity that Check Point later confirmed starting September 12, giving defenders a two-day window to apply updates before mass attempts began.<\/p>\n<p>CISA has now added both flaws to its Known Exploited Vulnerabilities (KEV) catalog and directed federal agencies to apply available fixes or mitigations by September 25, 2026.<\/p>\n<h2>How to patch Security Gateway<\/h2>\n<p>Check Point&#8217;s advisory on CVE-2026-85102 recommends that administrators install Check Point LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways. Where LivePatch is not used, a fixed Jumbo Hotfix is required: R81.20 Take 166, R82 Take 126, R82.10 Take 44, or R81.10 Take 190, or later.<\/p>\n<p>Spark firewall customers should update to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later. Check Point also warns that some customers who installed an earlier offline LivePatch package still need Take 26 for full coverage.<\/p>\n<p>Administrators can confirm that LivePatch is active by running the <code>cpinfo -y CPupdates<\/code> command on the Security Gateway in expert mode.<\/p>\n<h2>Mitigations when patching is not yet possible<\/h2>\n<p>Where a fix cannot be applied immediately, Check Point recommends disabling the VPN implied rules and writing explicit rules that restrict Site-to-Site VPN on UDP\/500 and UDP\/4500 to specific peer IP addresses. For Remote Access VPN, the guidance is to allow only the required services over UDP\/500, UDP\/4500, TCP\/443, and TCP\/80 where applicable, and to restrict source client IP ranges where possible. Check Point notes that these mitigations do not apply to locally managed Spark firewalls.<\/p>\n<p>For hunting and mitigation advice specific to the Management web service CVE-2026-93616, Check Point directs administrators to a separate support article.<\/p>\n<h2>What defenders should do next<\/h2>\n<p>Anyone running Security Gateway on a supported branch should treat the September 25 CISA deadline as a hard date and confirm LivePatch status before that day. Hunt for the three certificate subjects listed above in VPN logs, but treat that list as a starting point rather than a complete indicator set, since Check Point has stated that more subjects may be in use. For environments that cannot update in time, the explicit VPN rule set on UDP\/500, UDP\/4500, TCP\/443, and TCP\/80 reduces the exposed surface while the patch is staged.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is CVE-2026-85102?<\/h3>\n<p>CVE-2026-85102 is a pre-authentication remote code execution vulnerability in the VPN certificate-handling functionality of Check Point Security Gateway. Check Point confirmed active exploitation beginning on September 12, 2026.<\/p>\n<h3>When did exploitation of CVE-2026-93616 start?<\/h3>\n<p>Exploitation of CVE-2026-93616, a pre-authentication path traversal flaw in the Management web service, has been observed as a zero-day since July 23, 2026, according to Check Point.<\/p>\n<h3>What is the CISA deadline for these flaws?<\/h3>\n<p>CISA added both CVE-2026-85102 and CVE-2026-93616 to its Known Exploited Vulnerabilities catalog and set a remediation deadline of September 25, 2026 for federal agencies.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is CVE-2026-85102?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CVE-2026-85102 is a pre-authentication remote code execution vulnerability in the VPN certificate-handling functionality of Check Point Security Gateway. Check Point confirmed active exploitation beginning on September 12, 2026.\"}},{\"@type\":\"Question\",\"name\":\"When did exploitation of CVE-2026-93616 start?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Exploitation of CVE-2026-93616, a pre-authentication path traversal flaw in the Management web service, has been observed as a zero-day since July 23, 2026, according to Check Point.\"}},{\"@type\":\"Question\",\"name\":\"What is the CISA deadline for these flaws?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CISA added both CVE-2026-85102 and CVE-2026-93616 to its Known Exploited Vulnerabilities catalog and set a remediation deadline of September 25, 2026 for federal agencies.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw\/\" target=\"_blank\" rel=\"nofollow noopener\">bleepingcomputer.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Check Point confirms active exploitation of CVE-2026-85102 and CVE-2026-93616 in Security Gateway. CISA adds both to its KEV catalog with a September 25<\/p>\n","protected":false},"author":1,"featured_media":993,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rank_math_title":"Check Point Security Gateway VPN RCE flaw exploited","rank_math_description":"Check Point confirms active exploitation of CVE-2026-85102 and CVE-2026-93616 in Security Gateway. CISA adds both to its KEV catalog with a Sept 25 deadline.","rank_math_focus_keyword":"check point security gateway","rank_math_canonical_url":"","rank_math_facebook_title":"","rank_math_facebook_description":"","rank_math_twitter_title":"","rank_math_twitter_description":"","rank_math_robots":[],"footnotes":""},"categories":[14],"tags":[],"class_list":["post-994","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-news"],"_links":{"self":[{"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/posts\/994","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/comments?post=994"}],"version-history":[{"count":1,"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/posts\/994\/revisions"}],"predecessor-version":[{"id":995,"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/posts\/994\/revisions\/995"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/media\/993"}],"wp:attachment":[{"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/media?parent=994"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/categories?post=994"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/tags?post=994"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}