Skip to main content

Exploitation of Vulnerabilities affecting Check Point Appliances

Successful exploitation of CVE-2026-85102 or CVE-2026-93616 could allow an unauthenticated remote attacker to compromise Security Gateway, Spark Firewall, or Security Management

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation of CVE-2026-85102 or CVE-2026-93616 could allow an unauthenticated remote attacker to compromise Security Gateway, Spark Firewall, or Security Management


Threat details

Active Exploitation of CVE-2026-85102 and CVE-2026-93616

Check Point have observed active exploitation of both CVE-2026-85102 and CVE-2026-93616 in the wild.

NHS England National CSOC assesses further exploitation as almost certain.


Introduction

Check Point has released a security advisory to address a critical vulnerability in their Security Gateway platform and a zero-day vulnerability affecting Security Management.

Successful exploitation of CVE-2026-85102 could allow an unauthenticated remote attacker to execute arbitrary code on a vulnerable gateway. Successful exploitation of CVE-2026-92616 could allow an attacker to execute a script from an arbitrary path and load an arbitrary Java class.

  • CVE-2026-85102 – Improper Certificate Trust Validation vulnerability – CVSSv3.1 score: 9.8
  • CVE-2026-93616 - Path Traversal vulnerability - CVSSv3.1 score: 9.8

Threat updates

Date Update
22 Sep 2026 Escalated to High Severity following reports of active exploitation

The following sections have been updated:

  • Title
  • Severity
  • Affected platforms
  • Exploitation details
  • Introduction
  • Remediation advice
  • Remediation steps
  • CVE identifier

Remediation advice

Affected organisations must review Check Point Security Advisory Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616 and apply the relevant update as soon as possible. 

Note: Organisations running end-of-life versions must upgrade to a supported version.


Remediation steps

Type Step
Patch

Required: Patch Security Gateway and Spark Firewall

Affected organisations must upgrade Security Gateway and Spark Firewall to a fixed version.


https://support.checkpoint.com/results/sk/sk1000117
Patch

Required: Patch Security Management Server

Affected organisations must upgrade Security Management Server and Multi-Domain Security Management Server to a fixed version.


https://support.checkpoint.com/results/sk/sk1000171


Last edited: 22 September 2026 4:50 pm