Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution vulnerability in the VPN certificate-handling functionality of its Security Gateway product.
Its advisory also warns of exploitation of CVE-2026-93616, a pre-authentication path traversal flaw affecting the Management web service. The flaw can allow script execution and Java class loading. Check Point says CVE-2026-93616 has been exploited as a zero-day since July 23.
The Dutch Nationaal Cyber Security Centrum alerted users on September 10, while Check Point said malicious activity against Spark customers began on September 12, 2026. The attempts came through VPN services and proxies. Check Point said three certificate subjects reflected current observations only, and that more subjects may be in use.
CISA has added both flaws to its Known Exploited Vulnerabilities catalog and urged federal agencies to apply fixes or mitigations by September 25, 2026. Check Point recommends LivePatch Take 26 for supported R81.20, R82, and R82.10 gateways, or fixed Jumbo Hotfix versions R81.20 Take 166, R82 Take 126, R82.10 Take 44, and R81.10 Take 190 or later. Spark firewalls should be updated to R82.00.10 Build 2325 or R81.10.17 Build 4968 or later.
The advisory also lists VPN mitigation rules involving UDP/500, UDP/4500, TCP/443, and TCP/80, where applicable. Check Point says these measures do not apply to locally managed Spark firewalls.
Comments
0No comments yet. Be the first to comment.