Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Check Point confirmed active attacks against CVE-2026-85102 beginning September 12, 2026, exactly three days after releasing fixes on September 9. The vulnerability, rated CVSS 9.8 per the vendor bulletin, allows pre-authentication remote code execution in the VPN certificate handling of Security Gateways. CISA added it to the KEV catalog on September 22 with a federal deadline of September 25, making it a national priority for U.S. government agencies.
- CVE-2026-85102 is a pre-authentication CVSS 9.8 vulnerability in VPN certificate handling on Check Point Security Gateways, not in the authentication path
- Patches have been available since September 9, 2026; confirmed exploitation began September 12 against Spark customers
- CISA added both CVEs to the KEV catalog on September 22 with a federal deadline of September 25 under BOD 26-04
- A second vulnerability, CVE-2026-93616 CVSS 9.8 in the management plane, was exploited as a zero-day starting July 23, 2026
The Mechanism: Why the Certificate Becomes a Weapon
The flaw lies in certificate data validation during IKEv1/IKEv2 VPN negotiation. According to the official support article sk1000117, an unauthenticated remote attacker can present a forged certificate and achieve arbitrary code execution on the Security Gateway before any authentication decision is made.
The technical distinction is critical: the vulnerable path is certificate processing, not authentication. Any network-reachable VPN endpoint can trigger the flow. Communities using only PSK (Pre-Shared Key) are not affected; DAIP and LSV configurations that enable certificate authentication are.
The Three-Day Window: From Reverse Engineering to Attack
Check Point publicly disclosed the vulnerability and distributed fixes on September 9. On September 12, it observed the first wave of exploitation attempts against Spark customers. The attacks originated from anonymization infrastructure, including VPN and proxy services. The vendor emphasizes that the list of observed certificate subjects is not exhaustive.
"A fix for CVE-2026-85102 has been available since September 9, and customers who have applied it are already protected" — Check Point Security Advisory
This three-day interval constitutes an operational case study. This is not zero-day exploitation: patches were available, but the speed of reverse engineering outpaces deployment in enterprise infrastructures. The availability of the fix becomes part of the problem, not just the solution, when adversaries can analyze binary diffs faster than organizations can plan maintenance.
The Second Front: CVE-2026-93616 and the Management Plane
The same Check Point bulletin reveals a separate vulnerability, CVE-2026-93616, also CVSS 9.8 but in the management plane. This was exploited as a zero-day starting July 23, 2026. The vendor confirmed "a handful of targeted attacks" against an equal number of customers. The architectural distinction is significant: while CVE-2026-85102 hits the VPN perimeter, CVE-2026-93616 affects the policy management server, with potential impact on the configuration and control of those same gateways.
The two vulnerabilities do not share the same vector or component, but their concurrence creates dual risk. An attacker with access to both the VPN gateway and the management server can compromise both the perimeter and the policies that govern it.
Immediate Actions
The following actions derive directly from official Check Point documents and the CISA KEV:
- Verify the installed version and apply the specific fixes: for R81.20 Take 166, for R82 Take 126, for R82.10 Take 44, for R81.10 Take 190. Spark Firewall systems require R82.00.10 Build 2325 or R81.10.17 Build 4968 or later
- Evaluate applying LivePatch Take 26 for immediate mitigation, with awareness that Takes 28 and 29 do not resolve CVE-2026-93616
- Run the IoC queries published in support articles sk1000117 and sk1000171 to detect past exploitation attempts; the vendor provides specific strings for log searches
- For organizations with CISA federal deadlines, comply with BOD 26-04 with completion by September 25, 2026
The vendor specifies that locally managed Spark appliances do not fall under the same automated remediation flows and require dedicated attention.
Timeline and Federal Priorities
The consolidated timeline shows two distinct rhythms: CVE-2026-93616 operated in zero-day mode for nearly two months before a fix, while CVE-2026-85102 went from available patch to confirmed exploitation in 72 hours. CISA aggregated both into the KEV catalog on September 22, setting the same federal deadline of September 25 regardless of the initial discovery date.
This administrative choice reflects a risk logic: confirmation of active exploitation, not merely the technical existence of the vulnerability, determines KEV inclusion. For government agencies, the distinction between one-day and zero-day is operationally secondary to the finding that both are subject to ongoing attacks.
No infrastructural attribution linking the attacks to a specific actor emerges in the current state of documents. The vendor has not declared confirmed compromises for CVE-2026-85102, limiting itself to confirming attempts; the exact number of organizations hit by CVE-2026-93616 remains indicated as "a handful" without further precision.
The case raises a structural question for security operations: the time between disclosure and exploitation is converging toward 48-72 hour windows, making traditional patch cycles unsustainable. The ability to apply critical fixes on the same day as release, rather than the following weekend or next change window, is becoming the discriminator between resilience and compromise.
Sources
- https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
- https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/
- https://threataft.com/articles/check-point-vpn-cve-2026-85102-cve-2026-85103-unauthenticated-rce
- https://www.rescana.com/post/checkpoint-gateway-management-cve-2026-85102-93616-kev
- https://nvd.nist.gov/vuln/detail/CVE-2026-85102
- https://nvd.nist.gov/vuln/detail/CVE-2026-93616
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://support.checkpoint.com/results/sk/sk1000117
- https://support.checkpoint.com/results/sk/sk1000171/
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.