INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Check Point Warns of Zero-Day Exploited Security Gateway VPN Flaw

| 2026-09-23 19:53 CRITICAL HIGH
Executive Summary AI-generated
The situation is critical, with multiple vulnerabilities exploited by threat actors across various systems and networks. Check Point has confirmed the presence of two pre-authentication remote code execution (RCE) vulnerabilities in its Security Gateway product, CVE-2026-85102 and CVE-2026-93616. These exploits have been active since September 23, with malicious activity starting on September 12. The company recommends installing LivePatch Take 26 or a fixed Jumbo Hotfix: R81.20 to mitigate the risk. Customers are advised to update Spark firewalls to R82.00.10 Build 2325 or later, and take specific measures to restrict Site-to-Site VPN on UDP/500 and UDP/4500 to prevent exploitation of Management web service vulnerabilities. The situation demands immediate attention from system administrators, with Check Point urging federal agencies to apply available fixes by September 25, 2026.
Technical Mitigations AI-generated
• Update Security Gateway and Management web service: Customers should update their Spark firewalls to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later, as well as apply available security updates for CVE-2026-85102. • Disable VPN implied rules and create explicit rules: For Remote Access VPN, allow only the required services over UDP/500, UDP/4500, TCP/443, and TCP/80 where applicable, and restrict source client IP ranges where possible. Additionally, disable VPN implied rules for Site-to-Site VPN on UDP/500 and UDP/4500. • Use Check Point LivePatch Take 26: Install Check Point LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways to fix the CVE-2026-85102 vulnerability. • Verify if LivePatch is active by running cpinfo -y CPupdates command: In expert mode, verify that LivePatch is active and consider disabling VPN implied rules for Site-to-Site VPN on UDP/500 and UDP/4500.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SparkSpark CVE-2026-85103CVE-2026-85103 CVE-2026-85102CVE-2026-85102 CVE-2026-93616CVE-2026-93616 CVE-2026-91843CVE-2026-91843 CVE-2026-16232CVE-2026-16232 CVE-2026-50751CVE-2026-50751
Target & Sectors
BENELUX BENELUX
Incident Timeline
‎June 8
Threat actors exploited a known flaw in the Check Point management servers.
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
‎July 23
Attackers exploited a previously unknown flaw in Check Point's Security Management Server.
vulnerability CVE-2026-93616
organisation CVE-2026
tactic T1584.004 - Server
organisation Network Security / Vulnerability
organisation Check Point's
organisation Security Management
general_metric 22 Sep
‎September 1
Threat actors exploited a known vulnerability in Check Point's Management Servers.
general_metric 18 Take
‎September 9
Check Point addressed the CVE-2026-85103 VPN certificate flaw on September 9 by issuing fixes for the vulnerability.
organisation Check Point
vulnerability CVE-2026-85103
‎September 10
Threat actors exploited a known vulnerability in the Security Gateway, compromising management servers.
organisation NCSC
‎September 12, 2026
Threat actors exploited a known flaw in Spark management servers.
malware Spark
‎September 12
Check Point's management servers were targeted by attackers exploiting a previously fixed VPN flaw.
organisation Check Point
‎September 14, 2026
Check Point's management servers were exploited to target VPN connections.
‎September 16
Check Point fixed a separate flaw in the management server on September 16 through LivePatch.
vulnerability CVE-2026-91843
‎September 22, 2026
Check Point's Security Management Servers were compromised due to an actively exploited flaw allowing attackers to upload and run scripts.
organisation Security Management Servers
‎Sep 22, 2026
Threat actors exploited a known vulnerability in Check Point management servers.
‎September 22
Check Point released a fix on the server that controls firewall policies for its gateways.
‎2026/09/23
Check Point released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server.
organisation Check Point LivePatch Take
organisation CVE-2026
organisation the Dutch National Cyber Security Centre
organisation Check Point VPN
organisation NCSC
organisation The Dutch Nationaal Cyber Security Centrum
organisation Check Point
organisation Security Gateways and Security Management Servers
organisation Security Management
infrastructure 00.10
infrastructure 10.17
organisation Jumbo Hotfix
organisation IP
organisation UDP
organisation LivePatch
organisation CPupdates
organisation pushes urgent fixes
organisation Site‑to‑Site VPN
organisation NFL
organisation CHANEL
organisation R81
organisation R80.20
organisation R80
organisation National Cyber Security Centre
organisation Multi-Domain Security Management
organisation SmartEvent
organisation the Security Management
organisation Check Point's
organisation Security Gateways
organisation CVSS
organisation EoS
organisation The Hacker News
organisation Mobile Access
organisation Remote Access VPN
data_breach 9 September
organisation Check Point Fixes
organisation Manage & Settings → Permissions & Administrators
organisation SmartConsole
organisation SecurityAffairs
organisation LivePatch Take
organisation IOC
organisation PoC
organisation Quantum Security Management
organisation Quantum Security Gateway
organisation Quantum
organisation the Canadian Center for Cyber Security
organisation R82.00
‎September 25, 2026
Threat actors exploited a flaw in management servers.
tactic T1588.006 - Vulnerabilities
attribution KEV
Tactical Metrics
Metrics
infrastructure
‎00.10
Software Version
Metrics
infrastructure
‎10.17
Software Version
Metrics
data_breach
9
September