Check Point reports active exploitation of CVE-2026-85102 and CVE-2026-93616
News

Check Point reports active exploitation of CVE-2026-85102 and CVE-2026-93616

2 min read

Check Point reported active exploitation of flaws affecting Security Gateway and Security Management. CISA added both CVEs to its KEV Catalog, and fixes are available.

In a September 22, 2026 security advisory, Check Point reported active exploitation of CVE-2026-85102 and CVE-2026-93616, which affect Security Gateway and Security Management. CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog the same day, citing evidence of active exploitation.

Check Point also described CVE-2026-93616 as a newly discovered zero-day vulnerability affecting Security Management. The company said a fix became available with its September 22 advisory.

Technical scope of the vulnerabilities

CVE-2026-85102: VPN certificate handling

CVE-2026-85102 is a pre-authentication remote code execution vulnerability in Security Gateway’s VPN certificate handling.

Check Point said it had observed exploitation attempts against Spark customers globally. The advisory does not report a successful breach or a verified victim count. Its wording is: “We are now observing exploitation attempts against Check Point Spark customers globally.”

CVE-2026-93616: Security Management path traversal

CVE-2026-93616 is a pre-authentication path traversal vulnerability in the Security Management web service. According to Check Point, it allows an attacker to execute a script from an arbitrary path and load an arbitrary Java class. The company said that, as of the advisory’s publication, it had observed a handful of targeted attacks on July 23, 2026; it did not provide a broader victim count or attack volume.

CISA listing and remediation priority

CISA stated the basis for four new KEV entries as follows: “CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.” CVE-2026-85102 and CVE-2026-93616 were among those entries.

The KEV listing supports the finding that both vulnerabilities are being exploited, but CISA’s alert does not independently identify victims, quantify attack volume or establish impact. Check Point called for available fixes to be applied promptly on affected versions, while CISA encouraged all organizations to prioritize remediation of KEV vulnerabilities through risk-based vulnerability management.

#check point#cve-2026-85102#cve-2026-93616#active exploitation#cisa kev
Back to all updates