Published on September 24, 2026
Hackers Exploit Check Point VPN RCE and Management Zero-Day in Attacks
Check Point has disclosed two critical vulnerabilities, CVE-2026-85102 and CVE-2026-93616, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.8 and can be exploited remotely without authentication.
CVE-2026-85102 is an improper certificate-validation flaw affecting Check Point Security Gateway and Spark Firewall VPN deployments. Successful exploitation may allow an unauthenticated attacker to execute arbitrary code during VPN negotiation. Check Point released fixes on September 9 but later observed exploitation attempts against Spark Firewalls beginning September 12. The affected products include Security Gateway and centrally or locally managed Spark Firewall devices running versions R81 through R82.10, while R82.20 is not affected.
CVE-2026-93616 is a pre-authentication directory traversal and file-upload vulnerability affecting Check Point Management web services. An unauthenticated attacker could exploit the flaw to upload and execute arbitrary scripts on a Management Server. Check Point has reported a limited number of targeted attacks. Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Smart-1 Cloud, Check Point Firewall Appliances, and Spark Firewalls are not affected.
How?
Attackers can exploit CVE-2026-85102 remotely during VPN authentication by abusing certificate-validation weaknesses to gain code execution. Check Point observed malicious certificates and connections originating from VPN services and proxy infrastructure. Organizations should also be aware that the identified certificate subjects are not exhaustive.
For CVE-2026-93616, attackers can exploit the vulnerable Management web services before authentication by using directory traversal techniques to upload malicious files or scripts, which can then be executed on the affected Management Server.
Recommendation
Organizations should immediately apply the relevant Check Point security hotfixes or updated Jumbo Hotfix Accumulators and ensure internet-facing VPN and management services are not unnecessarily exposed. Access to the Security Management Server should be restricted behind a Check Point gateway or firewall, with TCP/19009 limited to trusted IP addresses.
Security teams should review Mobile Access and VPN logs for suspicious certificate-authentication activity, unusual internal port or service scanning, and unusually long usernames in cpm.elg. They should also investigate related FWM/MDS core dumps and errors containing directory traversal patterns such as ../.
Source
https://gbhackers.com/hackers-exploit-check-point-vpn-rce-and-management-zero-day/
