Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
New Android Banking Trojan Steals PINs with AI-Generated Overlays
September 24, 2026
Microsoft Unveils AI-Powered Security Copilot and SIEM for SOC Modernization
September 24, 2026
OpenAI Agent Did Not Hack Australian Medicare Portal, Vendor Clarifies
September 24, 2026
Home/CyberSecurity News/Critical Check Point VPN Flaws Let Attackers Gain Remote Access Without Login
CyberSecurity News

Critical Check Point VPN Flaws Let Attackers Gain Remote Access Without Login

Key Takeaways Check Point has issued an urgent warning regarding two critical vulnerabilities (CVE-2026-85102 and CVE-2026-93616) in its VPN and management products. Both flaws carry a CVSS score of...

Sarah simpson
Sarah simpson
September 24, 2026 3 Min Read
5 0

Key Takeaways

  • Check Point has issued an urgent warning regarding two critical vulnerabilities (CVE-2026-85102 and CVE-2026-93616) in its VPN and management products.
  • Both flaws carry a CVSS score of 9.8, allowing unauthenticated remote access and potential remote code execution.
  • Attackers are actively exploiting both vulnerabilities in the wild.
  • Patches and hotfixes are available and should be applied immediately to affected systems.

Check Point has issued a critical alert, confirming that threat actors are actively exploiting two severe vulnerabilities within its VPN and security management offerings. These flaws could grant unauthorized remote access and, in some scenarios, facilitate remote code execution on vulnerable systems. Organizations relying on Check Point products are strongly advised to deploy available fixes without delay.

Table Of Content

  • Key Takeaways
  • CVE-2026-85102: VPN Flaw Enables Remote Code Execution
  • Check Point VPN Flaws Exploit
  • CVE-2026-93616: Zero-Day in Management Servers
  • What You Should Do

Both identified vulnerabilities have been assigned a critical CVSS severity score of 9.8, underscoring the significant risk they pose. Check Point has developed and released patches designed to address these issues, emphasizing the immediate need for affected entities to apply them.

CVE-2026-85102: VPN Flaw Enables Remote Code Execution

The first vulnerability, identified as CVE-2026-85102, impacts Check Point Security Gateway and Spark Firewall deployments configured for Remote Access VPN or certificate-based Site-to-Site VPN authentication. This flaw originates from insufficient validation of certificate data during the VPN negotiation process.

Exploitation of CVE-2026-85102 could allow a remote attacker to execute arbitrary code on the affected system without requiring valid authentication credentials. Check Point initially released a patch for this vulnerability on September 9, 2026, at which point no active exploitation had been detected.

Check Point VPN Flaws Exploit

However, Check Point later confirmed that attempts to exploit CVE-2026-85102 began on September 12, specifically targeting Spark Firewall customers. These attacks were observed globally and originated from various anonymization infrastructures, including VPN services and proxy networks.

Indicators of compromise included suspicious VPN certificate subject values such as “CN=vpn, OU=users, O=global”; “CN=vpn-user, OU=users, O=global”; and “CN=vpnuser, OU=users, O=global”. It is important to note that these specific values are not exhaustive, and attackers may employ different certificate subjects in future attempts.

CVE-2026-93616: Zero-Day in Management Servers

The second critical vulnerability is a newly disclosed zero-day, CVE-2026-93616, which affects Check Point Security Management and Multi-Domain Security Management environments. This flaw is a pre-authentication directory traversal and file-upload vulnerability, enabling an attacker to upload and execute arbitrary scripts on an exposed management server. Check Point has confirmed a limited number of customers have been targeted by real-world attacks leveraging this vulnerability.

CVE-2026-93616 impacts several products, including Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Notably, Smart-1 Cloud, Check Point Firewall Appliances, and Check Point Spark Firewall are not susceptible to this particular management-server vulnerability.

The flaw allows an unauthenticated attacker to exploit directory traversal sequences, such as “../”, to bypass intended access restrictions and upload attacker-controlled content to arbitrary paths. Successful exploitation could grant an intruder the ability to execute malicious scripts on a highly privileged management platform. This could lead to severe consequences, including manipulation of firewall policies, theft of credentials, network reconnaissance, and lateral movement within the compromised network.

What You Should Do

  • Immediate Patching: Organizations utilizing vulnerable Check Point products must install the available Jumbo Hotfixes or security hotfixes without delay.
  • CVE-2026-85102 Fix: Ensure LivePatch Take 26 or later supported Jumbo Hotfix releases are applied. Check Point notes that R82.20 is not affected by this VPN issue.
  • CVE-2026-93616 Fix: Administrators should update to the R82.20 Security Hotfix or supported Jumbo Hotfix versions. Be aware that LivePatch Take 28 and Take 29 do not address this vulnerability, and a LivePatch is not available due to the nature of the required fix.
  • Monitor VPN Logs: Review Mobile Access logs for any anomalous certificate-based VPN logins. Investigate suspicious activity initiated by newly authenticated users, as internal port scanning or service discovery after a questionable VPN login could indicate a second stage of intrusion.
  • Restrict Management Server Access: For management servers, Check Point recommends restricting access to TCP port 19009 to trusted IP addresses only.
  • Inspect Management Logs: Security teams should examine management logs for unusually long usernames, error messages containing “ReflectionUtils,” and file paths that include directory traversal patterns. These artifacts may signal attempted exploitation of CVE-2026-93616.

The ongoing exploitation of both vulnerabilities underscores the critical importance of promptly patching internet-facing VPN and security-management infrastructure. These systems are frequently positioned at the network perimeter or oversee crucial security policies, rendering them prime targets for ransomware groups, access brokers, and state-sponsored threat actors.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchransomwareSecurityThreatVulnerabilityzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Roundcube SQL Injection CVE-2023-43770 Exploited in Attacks

Next Post

Galago Ransomware Emerges, Linked to Panzer Group

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Roundcube SQL Injection CVE-2023-43770 Exploited in Attacks
September 24, 2026
Malicious Firefox Extension Steals Google Account Sessions
September 24, 2026
Apache Tomcat Patches Critical WebSocket, HTTP/2 Vulnerabilities
September 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us