INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Check Point Warns of Zero-Day Exploited Security Gateway VPN Flaw
| 2026-09-23 19:53 CRITICAL HIGHExecutive Summary AI-generated
The situation is critical, with multiple vulnerabilities exploited by threat actors across various systems and networks. Check Point has confirmed the presence of two pre-authentication remote code execution (RCE) vulnerabilities in its Security Gateway product, CVE-2026-85102 and CVE-2026-93616. These exploits have been active since September 23, with malicious activity starting on September 12. The company recommends installing LivePatch Take 26 or a fixed Jumbo Hotfix: R81.20 to mitigate the risk. Customers are advised to update Spark firewalls to R82.00.10 Build 2325 or later, and take specific measures to restrict Site-to-Site VPN on UDP/500 and UDP/4500 to prevent exploitation of Management web service vulnerabilities. The situation demands immediate attention from system administrators, with Check Point urging federal agencies to apply available fixes by September 25, 2026.
Technical Mitigations AI-generated
• Update Security Gateway and Management web service: Customers should update their Spark firewalls to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later, as well as apply available security updates for CVE-2026-85102.
• Disable VPN implied rules and create explicit rules: For Remote Access VPN, allow only the required services over UDP/500, UDP/4500, TCP/443, and TCP/80 where applicable, and restrict source client IP ranges where possible. Additionally, disable VPN implied rules for Site-to-Site VPN on UDP/500 and UDP/4500.
• Use Check Point LivePatch Take 26: Install Check Point LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways to fix the CVE-2026-85102 vulnerability.
• Verify if LivePatch is active by running cpinfo -y CPupdates command: In expert mode, verify that LivePatch is active and consider disabling VPN implied rules for Site-to-Site VPN on UDP/500 and UDP/4500.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SparkSpark
CVE-2026-85103CVE-2026-85103
CVE-2026-85102CVE-2026-85102
CVE-2026-93616CVE-2026-93616
CVE-2026-91843CVE-2026-91843
CVE-2026-16232CVE-2026-16232
CVE-2026-50751CVE-2026-50751
Target & Sectors
BENELUX
BENELUX
Incident Timeline
June 8
Threat actors exploited a known flaw in the Check Point management servers.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog on June 8.
attribution
Known Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog on June 8.
July 23
Attackers exploited a previously unknown flaw in Check Point's Security Management Server.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-93616
The company says that CVE-2026-93616 has been exploited as a zero-day since July 23.
organisation
CVE-2026
The company says that CVE-2026-93616 has been exploited as a zero-day since July 23.
tactic
T1584.004 - Server
Swati Khandelwal
Sep 22, 2026
Network Security / Vulnerability
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23,
the company said
.
organisation
Network Security / Vulnerability
Swati Khandelwal
Sep 22, 2026
Network Security / Vulnerability
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23,
the company said
.
organisation
Check Point's
Swati Khandelwal
Sep 22, 2026
Network Security / Vulnerability
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23,
the company said
.
organisation
Security Management
Swati Khandelwal
Sep 22, 2026
Network Security / Vulnerability
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23,
the company said
.
general_metric
22 Sep
Swati Khandelwal
Sep 22, 2026
Network Security / Vulnerability
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23,
the company said
.
September 1
Threat actors exploited a known vulnerability in Check Point's Management Servers.
Click on any entity below to view its context and source!
general_metric
18 Take
Five separate accounts reported gateways were still on Take 18 or Take 17 of the urgent security update package on the day of the announcement; one of them posted an update log showing Take 18 installed on September 1 and nothing since.
September 9
Check Point addressed the CVE-2026-85103 VPN certificate flaw on September 9 by issuing fixes for the vulnerability.
Click on any entity below to view its context and source!
organisation
Check Point
Separately,
Check Point said
attackers have been trying since September 12 to exploit a VPN flaw it
fixed on September 9
.
On September 9, Check Point issued fixes for the flaws along with separate security advisories describing them:
sk1000117
and
sk1000118
.
Check Point disclosed the flaws on September 9 in a
notice to its customer community
, and began delivering fixes the same day.
vulnerability
CVE-2026-85103
CVE-2026-85103, a VPN certificate flaw that Check Point fixed on September 9, affected both gateways and management servers.
September 10
Threat actors exploited a known vulnerability in the Security Gateway, compromising management servers.
Click on any entity below to view its context and source!
organisation
NCSC
On September 10, the Dutch Nationaal Cyber Security Centrum
(NCSC) alerted
of the Security Gateway issue and urged users to apply available security updates as imminent exploitation was expected.
September 12, 2026
Threat actors exploited a known flaw in Spark management servers.
Click on any entity below to view its context and source!
malware
Spark
“Starting September 12, 2026, we observed a wave of exploitation attempts against Spark customers,”
reads Check Point’s alert
.
September 12
Check Point's management servers were targeted by attackers exploiting a previously fixed VPN flaw.
Click on any entity below to view its context and source!
organisation
Check Point
Separately,
Check Point said
attackers have been trying since September 12 to exploit a VPN flaw it
fixed on September 9
.
September 14, 2026
Check Point's management servers were exploited to target VPN connections.
September 16
Check Point fixed a separate flaw in the management server on September 16 through LivePatch.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-91843
On September 16, Check Point
fixed a separate flaw in the management server
, CVE-2026-91843, through LivePatch.
September 22, 2026
Check Point's Security Management Servers were compromised due to an actively exploited flaw allowing attackers to upload and run scripts.
Click on any entity below to view its context and source!
organisation
Security Management Servers
Check Point Fixes a New Actively Exploited Critical Security Flaw
Pierluigi Paganini
September 22, 2026
Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers.
Sep 22, 2026
Threat actors exploited a known vulnerability in Check Point management servers.
September 22
Check Point released a fix on the server that controls firewall policies for its gateways.
2026/09/23
Check Point released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server.
Click on any entity below to view its context and source!
organisation
Check Point LivePatch Take
Mitigating the risk
Check Point’s
advisory on CVE-2026-85102
recommends that administrators install Check Point LivePatch Take 26 on supported R81.20, R82, or R82.10 gateways, or install a fixed Jumbo Hotfix: R81.20
Both flaws are fixed by Check Point LivePatch Take 24 for R81.20, R82, and R82.10, while fixes are also included in the following versions:
organisation
CVE-2026
Two weeks ago, the Dutch National Cyber Security Centre
warned
of two critical Check Point VPN flaws, tracked as CVE-2026-85102 and CVE-2026-85103, saying it expected exploitation attempts to start soon.
“There are 2 critical vulnerabilities in Check Point VPN products with the attributes CVE-2026-85102 and CVE-2026-85103.
CVE-2026-85102 is an improper validation of certificate data during VPN negotiation that a remote attacker could exploit to execute arbitrary code on a Security Gateway.
In the same community thread, a Check Point staff member was asked whether gateways with the VPN software blade turned off are affected by CVE-2026-85103.
organisation
the Dutch National Cyber Security Centre
Two weeks ago, the Dutch National Cyber Security Centre
warned
of two critical Check Point VPN flaws, tracked as CVE-2026-85102 and CVE-2026-85103, saying it expected exploitation attempts to start soon.
organisation
Check Point VPN
Two weeks ago, the Dutch National Cyber Security Centre
warned
of two critical Check Point VPN flaws, tracked as CVE-2026-85102 and CVE-2026-85103, saying it expected exploitation attempts to start soon.
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited.
organisation
NCSC
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
For gateways that cannot be patched yet, the NCSC lists a Check Point workaround for Site-to-Site VPN: turn off the implied VPN rules and allow UDP ports 500 and 4500 only from specific peer IP addresses.
Both vulnerabilities can be triggered by external attackers, and while no public proof‑of‑concept has surfaced yet, the NCSC explicitly rates the likelihood of exploitation and the potential damage as high.
organisation
The Dutch Nationaal Cyber Security Centrum
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
organisation
Check Point
Two critical Check Point VPN flaws score 9.8 and could enable remote code execution.
Check Point notes that these mitigation measures do not apply to locally managed Spark firewalls.
Because the Management Server controls security policies, admin activity and system logs across Check Point deployments, a compromise could have a wider impact on an enterprise network.
organisation
Security Gateways and Security Management Servers
CVE‑2026‑85103 is a heap overflow in the certificate ASN.1 decoder that also leads to remote code execution on Security Gateways and Security Management Servers.
CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder that could allow remote code execution on Security Gateways and Security Management Servers.
organisation
Security Management
Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server.
Neither Check Point's notice nor any public record reviewed for this article states which Spark or Security Management versions are affected, which builds contain the fix, or what specific conditions the company says the flaws require.
infrastructure
00.10
Customers should also update Spark firewalls to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later.
R82.10 Jumbo Hotfix Accumulator Take 44 or later
R82 Jumbo Hotfix Accumulator Take 126 or later
R81.20 Jumbo Hotfix Accumulator Take 166 or later
Spark R82.00.10 Build 2325 or later
Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is not affected by either flaw.
infrastructure
10.17
Customers should also update Spark firewalls to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later.
R82.10 Jumbo Hotfix Accumulator Take 44 or later
R82 Jumbo Hotfix Accumulator Take 126 or later
R81.20 Jumbo Hotfix Accumulator Take 166 or later
Spark R82.00.10 Build 2325 or later
Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is not affected by either flaw.
organisation
Jumbo Hotfix
R82.10 Jumbo Hotfix Accumulator Take 44 or later
R82 Jumbo Hotfix Accumulator Take 126 or later
R81.20 Jumbo Hotfix Accumulator Take 166 or later
Spark R82.00.10 Build 2325 or later
Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is not affected by either flaw.
organisation
IP
For gateways that cannot be patched yet, the NCSC lists a Check Point workaround for Site-to-Site VPN: turn off the implied VPN rules and allow UDP ports 500 and 4500 only from specific peer IP addresses.
If updating isn’t possible, it is recommended to disable the VPN implied rules and create explicit rules that restrict Site-to-Site VPN on UDP/500 and UDP/4500 to specific peer IP addresses.
If the hotfix cannot be installed immediately, the cybersecurity firm recommends placing the vulnerable system behind a firewall and allowing access only from trusted IP addresses.
For organizations using Site‑to‑Site VPN, it also recommends tightening the ruleset: disable implied rules and restrict VPN access to specific, trusted IP addresses instead of leaving it wide open.
At the same time, for those using the ‘Site-to-Site VPN’ component, the advice is to modify VPN rules to limit access to specific, trusted IP addresses.
organisation
UDP
For gateways that cannot be patched yet, the NCSC lists a Check Point workaround for Site-to-Site VPN: turn off the implied VPN rules and allow UDP ports 500 and 4500 only from specific peer IP addresses.
organisation
LivePatch
System administrators are advised to verify if LivePatch is active by running the
cpinfo -y CPupdates
command on the Security Gateway in expert mode.
Its LivePatch channel, which pushes urgent fixes, uses a separate set of take numbers.
If you use LivePatch with R81.20, R82 or R82.10, your system may already be protected without a reboot.
organisation
CPupdates
System administrators are advised to verify if LivePatch is active by running the
cpinfo -y CPupdates
command on the Security Gateway in expert mode.
organisation
pushes urgent fixes
Its LivePatch channel, which pushes urgent fixes, uses a separate set of take numbers.
organisation
Site‑to‑Site VPN
For organizations using Site‑to‑Site VPN, it also recommends tightening the ruleset: disable implied rules and restrict VPN access to specific, trusted IP addresses instead of leaving it wide open.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
R81
The CVE record lists these versions as affected:
R82.20 with no Jumbo Hotfix installed
R82.10 with Jumbo Hotfix Take 44 or below
R82 with Jumbo Hotfix Take 126 or below
R81.20 with Jumbo Hotfix Take 166 or below
R81.10 with Jumbo Hotfix Take 190 or below (end of support)
R81, R80.40, R80.30, R80.20, R80.10 and R80 (all end of support)
Check Point's advisory lists R82.20 as affected without the "no Jumbo Hotfix" condition.
Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, along with the end-of-support (EoS) versions R80 through R80.40, R81, and R81.10.
organisation
R80.20
The CVE record lists these versions as affected:
R82.20 with no Jumbo Hotfix installed
R82.10 with Jumbo Hotfix Take 44 or below
R82 with Jumbo Hotfix Take 126 or below
R81.20 with Jumbo Hotfix Take 166 or below
R81.10 with Jumbo Hotfix Take 190 or below (end of support)
R81, R80.40, R80.30, R80.20, R80.10 and R80 (all end of support)
Check Point's advisory lists R82.20 as affected without the "no Jumbo Hotfix" condition.
organisation
R80
The CVE record lists these versions as affected:
R82.20 with no Jumbo Hotfix installed
R82.10 with Jumbo Hotfix Take 44 or below
R82 with Jumbo Hotfix Take 126 or below
R81.20 with Jumbo Hotfix Take 166 or below
R81.10 with Jumbo Hotfix Take 190 or below (end of support)
R81, R80.40, R80.30, R80.20, R80.10 and R80 (all end of support)
Check Point's advisory lists R82.20 as affected without the "no Jumbo Hotfix" condition.
The affected releases span R81.20, R82, R82.10, R81.10.x and R82.00.x, plus end‑of‑support versions from R80 through R81.10.
organisation
National Cyber Security Centre
The Netherlands'
National Cyber Security Centre (NCSC)
says the flaw applies when these products use Site-to-Site VPN or Remote Access VPN.
organisation
Multi-Domain Security Management
The impacted products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
organisation
SmartEvent
The impacted products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
organisation
the Security Management
The other affects those gateways and the Security Management Server, the console used to configure them.
organisation
Check Point's
One flaw affects Check Point's Security Gateways, its firewall appliances.
organisation
Security Gateways
One flaw affects Check Point's Security Gateways, its firewall appliances.
organisation
CVSS
Check Point rated it 9.8 out of 10 on the CVSS scale in the
CVE record
for the flaw.
The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited.
Both records carry a CVSS score of 9.8.
organisation
EoS
Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, along with the end-of-support (EoS) versions R80 through R80.40, R81, and R81.10.
organisation
The Hacker News
The Hacker News has asked Check Point about other affected products, the fixed builds, and the July attacks.
organisation
Mobile Access
Administrators should check logs for any unusual certificate-based Mobile Access login, not only those with these subjects.
June's was
CVE-2026-50751
, an authentication bypass in Remote Access VPN and Mobile Access certificate validation.
organisation
Remote Access VPN
June's was
CVE-2026-50751
, an authentication bypass in Remote Access VPN and Mobile Access certificate validation.
data_breach
9 September
Check Point says customers who installed the September 9 fix are protected, but its advisory does not say whether any attempt succeeded.
organisation
Check Point Fixes
Check Point Fixes a New Actively Exploited Critical Security Flaw.
organisation
Manage & Settings → Permissions & Administrators
This can be configured through Manage & Settings → Permissions & Administrators → Trusted Clients in SmartConsole.
organisation
SmartConsole
This can be configured through Manage & Settings → Permissions & Administrators → Trusted Clients in SmartConsole.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, BigDiskBuster)
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Check Point)
organisation
LivePatch Take
For supported versions, Check Point provides fixes through LivePatch Take 24 or specific Jumbo Hotfix updates, depending on the version you use.
organisation
IOC
If you’re not sure whether you’re running a vulnerable version, talk to your IT provider now, not after the first IOC shows up in your logs.
organisation
PoC
Although no public proof-of-concept (PoC) exploit has been reported, the agency is urging organizations to install the security updates addressing the two issues as soon as possible.
organisation
Quantum Security Management
Its record says an unauthenticated remote attacker may be able to run code on Quantum Security Management and Quantum Security Gateway systems.
organisation
Quantum Security Gateway
Its record says an unauthenticated remote attacker may be able to run code on Quantum Security Management and Quantum Security Gateway systems.
organisation
Quantum
The list covers three Quantum branches and gives no version information for anything else.
organisation
the Canadian Center for Cyber Security
An
advisory from the Canadian Center for Cyber Security
, published the same evening, lists a broader set of products but no versions at all.
organisation
R82.00
A Check Point employee said in the thread that it can be installed on top of any Jumbo Hotfix level in R81.20, R82.00 and R82.10, and named only those three versions.
September 25, 2026
Threat actors exploited a flaw in management servers.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
CISA has now added the two flaws in its Known Exploited Vulnerabilities
(KEV) catalog
, urging federal agencies to apply the available fixes and/or mitigations by September 25, 2026.
attribution
KEV
CISA has now added the two flaws in its Known Exploited Vulnerabilities
(KEV) catalog
, urging federal agencies to apply the available fixes and/or mitigations by September 25, 2026.
Tactical Metrics
Metrics
infrastructure
00.10
Software Version
Click for context!
Customers should also update Spark firewalls to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later.
R82.10 Jumbo Hotfix Accumulator Take 44 or later
R82 Jumbo Hotfix Accumulator Take 126 or later
R81.20 Jumbo Hotfix Accumulator Take 166 or later
Spark R82.00.10 Build 2325 or later
Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is not affected by either flaw.
Metrics
infrastructure
10.17
Software Version
Customers should also update Spark firewalls to R82.00.10 Build 2325 or R81.10.17 Build 4968, or later.
R82.10 Jumbo Hotfix Accumulator Take 44 or later
R82 Jumbo Hotfix Accumulator Take 126 or later
R81.20 Jumbo Hotfix Accumulator Take 166 or later
Spark R82.00.10 Build 2325 or later
Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is not affected by either flaw.
Metrics
data_breach
9
September
Check Point says customers who installed the September 9 fix are protected, but its advisory does not say whether any attempt succeeded.
Intelligence Sources
The Hacker News
2026-09-10
BleepingComputer
2026-09-12
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
BleepingComputer
Security Affairs
2026-09-14
The Hacker News
2026-09-22
Security Affairs
2026-09-22
Check Point Fixes a New Actively Exploited Critical Security Flaw
Security Affairs
BleepingComputer
2026-09-23
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-24T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
46x
organisation
Identified Entity
CVE-2026
entity
16x
timeline
Temporal Reference
September 12, 2026
date
6x
vulnerability
Exploited CVE
CVE-2026-85102
cve
5x
attribution
Attributing Entity
KEV
authority
2x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
general metric
Livepatch
26
livepatch
2x
infrastructure
Software Version
00.10
version
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
target region
Target Country
France
country
2x
general metric
Hotfix
125
hotfix
Contextual Telemetry
Context Block
14 METRICS
general metric
Cve-2026
93,616
cve-2026
malware
Malware Payload
Spark
tool
general metric
Entities
166
entities
general metric
R82
126
r82
general metric
R81.10
190
r81.10
general metric
Flaw
85,102
flaw
general metric
Sep
22
sep
general metric
Udp Ports
500
udp ports
data breach
September
9
september
general metric
Vpn
10
vpn
vulnerability
CVSS Score
10
score
general metric
Critical Vulnerabilities
2
critical vulnerabilities
general metric
Attributes
85,103
attributes
general metric
Take
18
take
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.