Skip to content
TrustList
News

Two exploited Check Point flaws get a three-day federal patch deadline

Editorial

By TrustList Editorial

CISA added CVE-2026-85102 and CVE-2026-93616 to its exploited-vulnerabilities catalogue on 22 September with a remediation date of 25 September. Both are pre-authentication and both are rated 9.8; one has been under attack since 12 September.

About Two exploited Check Point flaws get a three-day federal patch deadline

Two exploited Check Point flaws get a three-day federal patch deadline

22 September 2026 — CISA added two Check Point vulnerabilities to its Known Exploited Vulnerabilities catalogue on 22 September 2026 and set the remediation date at 25 September — three days. Short due dates in that catalogue are reserved for things already being used, and both of these are.

The two flaws

CVE-2026-85102 is an improper validation of certificate data during VPN negotiation, reachable before authentication on Security Gateway and on Spark Firewall in both centrally and locally managed forms, across the R81 to R82.00.X range. Check Point rates it 9.8 and published a fix on 9 September. It began seeing a wave of exploitation attempts against Spark customers on 12 September — three days after the patch, which is the usual interval now.

CVE-2026-93616 is new. It is a pre-authentication path traversal in the Security Management web service that lets an attacker execute a script from an arbitrary path and load an arbitrary Java class; Check Point rates it 9.8 as well and shipped the fix with the advisory itself. Affected products are Security Management, Multi-Domain Security Management, Log Server, Multi-Domain Log Server and SmartEvent, at R82.20 and earlier hotfix levels. Check Point describes what it has seen as a handful of pinpointed attacks rather than mass exploitation.

Why the management server is the worse of the two

A gateway compromise is bad; a management server compromise is worse, and organisations routinely get the priority the wrong way round. The management server holds the policy for every gateway it manages, the logs those gateways send, and the credentials to push a new policy out. An attacker who reaches it does not need to break each gateway individually — they can change what the gateways are told to allow, and then delete the record of having done so.

That is also why exposure matters here. A Security Gateway is meant to face the internet. A Security Management server is not, and one that is reachable from outside is a configuration to fix regardless of this week's CVEs.

What to do about it

Install both fixes now rather than on the next maintenance window; the federal deadline is 25 September and the same reasoning applies outside government. Check Point's advisory points to its own support article for the version-by-version hotfix levels, which is the list to work from.

Then look back rather than forward. Check Point asks customers to review logs for anomalous certificate-based logins and for suspicious follow-on activity, particularly internal scanning from the gateway itself. For the management server, the equivalent question is whether any policy was installed or any administrator added in the past fortnight that nobody can account for. Patching closes the door; it does not tell you whether anyone came through it first.

Sources