CISA Warns of Critical Check Point Flaws Exploited in Attacks
Key Takeaways The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning regarding two Check Point vulnerabilities being actively exploited in the wild. The...
Key Takeaways
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning regarding two Check Point vulnerabilities being actively exploited in the wild.
- The exploited flaws, CVE-2026-85102 and CVE-2026-93616, affect various Check Point Security Gateway, Spark Firewall, and management/logging products.
- Both vulnerabilities allow unauthenticated remote attackers to execute arbitrary code or scripts, posing significant risks to affected organizations.
- CISA has added both to its Known Exploited Vulnerabilities (KEV) Catalog, setting a remediation deadline of September 25, 2026.
CISA Issues Urgent Warning for Exploited Check Point Flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has escalated warnings concerning two critical vulnerabilities impacting Check Point products, confirming that these flaws are under active exploitation by malicious actors. The agency has subsequently mandated immediate action by adding both vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog.
Table Of Content
These vulnerabilities collectively affect a broad spectrum of Check Point offerings, including Security Gateway, Spark Firewall, Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products.
CVE-2026-85102: Remote Code Execution via Improper Certificate Validation
The first vulnerability, identified as CVE-2026-85102, stems from an improper certificate validation flaw (CWE-295). This issue specifically impacts Check Point Security Gateway and Spark Firewall deployments configured for Site-to-Site or Remote Access VPN functionalities.
An unauthenticated remote attacker can leverage this weakness to achieve arbitrary code execution on a vulnerable gateway. This capability allows attackers to deploy malicious payloads or run commands without needing valid user credentials, presenting a severe risk, especially for organizations with exposed VPN services.
CVE-2026-93616: Path Traversal Leading to Arbitrary Script Execution
The second critical flaw, CVE-2026-93616, is a path traversal vulnerability (CWE-22) affecting several Check Point management and logging solutions. The impacted products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
This type of vulnerability enables attackers to access or manipulate files and directories beyond their intended restricted locations. In this specific case, an unauthenticated attacker can exploit the flaw to upload and execute arbitrary scripts. Successful exploitation could grant an attacker initial access within a security management environment, potentially paving the way for further network reconnaissance, credential theft, policy alterations, or malware deployment.
CISA’s Remediation Directive and Urgent Actions
CISA officially added both CVE-2026-85102 and CVE-2026-93616 to its KEV Catalog on September 22, 2026, setting a mandatory remediation deadline of September 25, 2026. The agency has strongly urged organizations to implement Check Point’s recommended mitigations, conduct thorough assessments of internet exposure, perform forensic triage, and, if necessary, discontinue affected products where mitigations are not feasible.
While CISA’s advisory currently lists the use of ransomware for these vulnerabilities as “unknown,” the inherent ability for unauthenticated code or script execution positions both flaws as high-priority risks for any organization utilizing the affected Check Point products.
What You Should Do
- Immediately identify all Check Point Security Gateway, Spark Firewall, Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent appliances within your environment.
- Prioritize patching and applying all available security updates and mitigations provided by Check Point for CVE-2026-85102 and CVE-2026-93616.
- Assess the public internet exposure of all identified Check Point products, particularly VPN services and management interfaces.
- Conduct a comprehensive review of authentication records, VPN activity logs, system logs, uploaded files, and any unusual script execution for signs of compromise, both before and after applying remediations.
- If mitigations are unavailable or incomplete, consider isolating or discontinuing affected products until a full resolution can be implemented.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.