Exploitation of Vulnerabilities affecting Check Point Appliances
Successful exploitation of CVE-2026-85102 or CVE-2026-93616 could allow an unauthenticated remote attacker to compromise Security Gateway, Spark Firewall, or Security Management
Summary
Successful exploitation of CVE-2026-85102 or CVE-2026-93616 could allow an unauthenticated remote attacker to compromise Security Gateway, Spark Firewall, or Security Management
Affected platforms
The following platforms are known to be affected:
Threat details
Active Exploitation of CVE-2026-85102 and CVE-2026-93616
Check Point have observed active exploitation of both CVE-2026-85102 and CVE-2026-93616 in the wild.
NHS England National CSOC assesses further exploitation as almost certain.
Introduction
Check Point has released a security advisory to address a critical vulnerability in their Security Gateway platform and a zero-day vulnerability affecting Security Management.
Successful exploitation of CVE-2026-85102 could allow an unauthenticated remote attacker to execute arbitrary code on a vulnerable gateway. Successful exploitation of CVE-2026-92616 could allow an attacker to execute a script from an arbitrary path and load an arbitrary Java class.
- CVE-2026-85102 – Improper Certificate Trust Validation vulnerability – CVSSv3.1 score: 9.8
- CVE-2026-93616 - Path Traversal vulnerability - CVSSv3.1 score: 9.8
Threat updates
| Date | Update |
|---|---|
| 22 Sep 2026 |
Escalated to High Severity following reports of active exploitation
The following sections have been updated:
|
Remediation advice
Affected organisations must review Check Point Security Advisory Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616 and apply the relevant update as soon as possible.
Note: Organisations running end-of-life versions must upgrade to a supported version.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Required: Patch Security Gateway and Spark Firewall Affected organisations must upgrade Security Gateway and Spark Firewall to a fixed version. https://support.checkpoint.com/results/sk/sk1000117 |
| Patch |
Required: Patch Security Management Server Affected organisations must upgrade Security Management Server and Multi-Domain Security Management Server to a fixed version. https://support.checkpoint.com/results/sk/sk1000171 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 22 September 2026 4:50 pm