threat_intelligence503 wordsRead on Arc Codex

460.23.09.26- Critical Check Point Vulnerabilities Under Active Exploitation

460.23.09.26- Critical Check Point Vulnerabilities Under Active Exploitation – CVE-2026-85102 and CVE-2026-93616 Severity: Critical CVSS Score: 9.8 Affected Vendor: Check Point Software Technologies Exploitation Status: Active exploitation observed Date: 23 September 2026 Overview The Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT) is advising organizations and system administrators of two (2) critical vulnerabilities affecting Check Point Security Gateway, Spark Firewall and Security Management products. The vulnerabilities are identified as CVE-2026-85102 and CVE-2026-93616, with both carrying a CVSS score of 9.8 and may allow an unauthenticated remote attacker to compromise affected systems. Organizations using the affected Check Point products are strongly advised to review their environment and apply the available security fixes immediately as both of the following vulnerabilities are being actively exploited in the wild: - CVE-2026-85102 – One day exploitation- Pre-authentication remote code execution vulnerability in Security Gateway’s VPN certificate handling - CVE-2026-85102– Zero-day, limited exploitation – Pre-authentication path traversal vulnerability in the Check Point Management web service Affected Products | CVE | Affected Products | Affected Versions | | CVE-2026-85102 | Security Gateway; Spark Firewall (Centrally Managed); Spark Firewall (Locally Managed) | R81 (EOS), R81.10 (EOS), R81.10.X, R81.10.X, R81.20, R82, R82.00.X, R82.00.X, R82.10 | | CVE-2026-93616 | Security Management | R82.20 R82.10 Jumbo Hotfix Take 44 or lower R82 Jumbo Hotfix Take 126 or lower R81.20 Jumbo Hotfix Take 166 or lower R81.10 Jumbo Hotfix Take 190 or lower (EoS) R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS) | Administrators should note that Check Point Live Patch Take 28/29 does not remediate CVE-2026-93616. Indicators and Detection For CVE-2026-85102, Check Point observed exploitation attempts originating from anonymization infrastructure, including VPN services and proxy networks. Observed malicious or suspicious certificate subjects include: CN=vpn,OU=users,O=global CN=vpn-user,OU=users,O=global CN=vpnuser,OU=users,O=global Organizations should review logs for: - Unusual certificate-based Mobile Access authentication; - Unexpected or unauthorized Mobile Access users; - Authentication originating from unusual or anonymized IP addresses; - Internal network, port or service scanning following a Mobile Access login; - Unusual administrative activity; - Unexpected scripts, Java classes or files on Security Management systems; - Other anomalous activity occurring before or following suspicious authentication events. Recommendations CVE-2026-85102 - Review your logs for anomalous certificate-based Mobile Access logins. - Look for second stage activity originating from suspicious logged-in users via Mobile Access. - Apply patches for CVE-2026-85102 via Check Point SK1000117 CVE-2026-93616 - Limit access to your Management Servers behind a Security Gateway/Check Point Firewall - Make sure that access to port TCP/19009 is only possible from Trusted IP addresses. - If you already have a Security Gateway / Check Point Firewall with implied rules enabled, make sure your Trusted Clients are limited to trusted internal IP addresses. - Apply patches for CVE-2026-93616 via Check Point SK1000171 References - Check Point Security Advisory – Active Exploitation of CVE-2026-85102 and CVE-2026-93616 Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616 – Check Point Blog - Check Point Security Knowledge Base – SK1000117 https://support.checkpoint.com/results/sk/sk1000117/ - Check Point Security Knowledge Base – SK1000171 https://support.checkpoint.com/results/sk/sk1000171/

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content β€” general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached β€” you'll always get the same 5 for this article.