Critical Check Point VPN Flaws Let Attackers Gain Remote Access Without Login
Key Takeaways Check Point has issued an urgent warning regarding two critical vulnerabilities (CVE-2026-85102 and CVE-2026-93616) in its VPN and management products. Both flaws carry a CVSS score of...
Key Takeaways
- Check Point has issued an urgent warning regarding two critical vulnerabilities (CVE-2026-85102 and CVE-2026-93616) in its VPN and management products.
- Both flaws carry a CVSS score of 9.8, allowing unauthenticated remote access and potential remote code execution.
- Attackers are actively exploiting both vulnerabilities in the wild.
- Patches and hotfixes are available and should be applied immediately to affected systems.
Check Point has issued a critical alert, confirming that threat actors are actively exploiting two severe vulnerabilities within its VPN and security management offerings. These flaws could grant unauthorized remote access and, in some scenarios, facilitate remote code execution on vulnerable systems. Organizations relying on Check Point products are strongly advised to deploy available fixes without delay.
Table Of Content
Both identified vulnerabilities have been assigned a critical CVSS severity score of 9.8, underscoring the significant risk they pose. Check Point has developed and released patches designed to address these issues, emphasizing the immediate need for affected entities to apply them.
CVE-2026-85102: VPN Flaw Enables Remote Code Execution
The first vulnerability, identified as CVE-2026-85102, impacts Check Point Security Gateway and Spark Firewall deployments configured for Remote Access VPN or certificate-based Site-to-Site VPN authentication. This flaw originates from insufficient validation of certificate data during the VPN negotiation process.
Exploitation of CVE-2026-85102 could allow a remote attacker to execute arbitrary code on the affected system without requiring valid authentication credentials. Check Point initially released a patch for this vulnerability on September 9, 2026, at which point no active exploitation had been detected.
Check Point VPN Flaws Exploit
However, Check Point later confirmed that attempts to exploit CVE-2026-85102 began on September 12, specifically targeting Spark Firewall customers. These attacks were observed globally and originated from various anonymization infrastructures, including VPN services and proxy networks.
Indicators of compromise included suspicious VPN certificate subject values such as “CN=vpn, OU=users, O=global”; “CN=vpn-user, OU=users, O=global”; and “CN=vpnuser, OU=users, O=global”. It is important to note that these specific values are not exhaustive, and attackers may employ different certificate subjects in future attempts.
CVE-2026-93616: Zero-Day in Management Servers
The second critical vulnerability is a newly disclosed zero-day, CVE-2026-93616, which affects Check Point Security Management and Multi-Domain Security Management environments. This flaw is a pre-authentication directory traversal and file-upload vulnerability, enabling an attacker to upload and execute arbitrary scripts on an exposed management server. Check Point has confirmed a limited number of customers have been targeted by real-world attacks leveraging this vulnerability.
CVE-2026-93616 impacts several products, including Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Notably, Smart-1 Cloud, Check Point Firewall Appliances, and Check Point Spark Firewall are not susceptible to this particular management-server vulnerability.
The flaw allows an unauthenticated attacker to exploit directory traversal sequences, such as “../”, to bypass intended access restrictions and upload attacker-controlled content to arbitrary paths. Successful exploitation could grant an intruder the ability to execute malicious scripts on a highly privileged management platform. This could lead to severe consequences, including manipulation of firewall policies, theft of credentials, network reconnaissance, and lateral movement within the compromised network.
What You Should Do
- Immediate Patching: Organizations utilizing vulnerable Check Point products must install the available Jumbo Hotfixes or security hotfixes without delay.
- CVE-2026-85102 Fix: Ensure LivePatch Take 26 or later supported Jumbo Hotfix releases are applied. Check Point notes that R82.20 is not affected by this VPN issue.
- CVE-2026-93616 Fix: Administrators should update to the R82.20 Security Hotfix or supported Jumbo Hotfix versions. Be aware that LivePatch Take 28 and Take 29 do not address this vulnerability, and a LivePatch is not available due to the nature of the required fix.
- Monitor VPN Logs: Review Mobile Access logs for any anomalous certificate-based VPN logins. Investigate suspicious activity initiated by newly authenticated users, as internal port scanning or service discovery after a questionable VPN login could indicate a second stage of intrusion.
- Restrict Management Server Access: For management servers, Check Point recommends restricting access to TCP port 19009 to trusted IP addresses only.
- Inspect Management Logs: Security teams should examine management logs for unusually long usernames, error messages containing “ReflectionUtils,” and file paths that include directory traversal patterns. These artifacts may signal attempted exploitation of CVE-2026-93616.
The ongoing exploitation of both vulnerabilities underscores the critical importance of promptly patching internet-facing VPN and security-management infrastructure. These systems are frequently positioned at the network perimeter or oversee crucial security policies, rendering them prime targets for ransomware groups, access brokers, and state-sponsored threat actors.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.