Summary
- CVE-2026-85102 exploitation attempts against Spark customers began on 12 September, three days after Check Point released a fix.
- CVE-2026-93616 affected Security Management and was observed in a handful of targeted attacks on 23 July before public disclosure.
- Both vulnerabilities have CVSS scores of 9.8 and affect security infrastructure positioned at trusted administrative boundaries.
Check Point has confirmed exploitation of two critical vulnerabilities affecting its Security Gateway and Security Management products, changing the risk calculation from preventative patching to potential compromise assessment for exposed customers.
CVE-2026-85102 is a pre-authentication remote-code-execution vulnerability caused by improper validation of certificate data during VPN negotiation. Check Point disclosed the flaw and released fixes on 9 September, when it said it had no evidence of exploitation.
The company now says a wave of exploitation attempts against Spark customers began on 12 September. The activity originated from anonymisation infrastructure including VPN services and proxies.
A second flaw, CVE-2026-93616, affects the Security Management web service. Check Point describes it as a pre-authentication path-traversal vulnerability capable of leading to arbitrary-path script execution and loading of an arbitrary Java class.
Check Point said it observed a handful of targeted attacks involving that vulnerability on 23 July, before the flaw had been publicly disclosed. A fix accompanied the September advisory.
Both vulnerabilities have CVSS scores of 9.8, but their operational significance is shaped by the systems they affect as much as the numerical severity. Security gateways and management servers sit at trusted control points used to enforce network policy, provide remote access, and administer other security infrastructure.
A compromise at that layer can have broader consequences than exploitation of an ordinary application server because the affected systems may already hold privileged relationships with other parts of an organisation.
The latest disclosure follows a separate Check Point management vulnerability disclosed earlier in September. CVE-2026-91843 was an unauthenticated stack overflow capable of allowing root-level code execution on management and logging systems, although Check Point said it had no indication of exploitation when that flaw was disclosed.
The newly confirmed attacks involve separate vulnerabilities and should not be conflated with that earlier issue. Together, however, the disclosures reinforce the concentration of risk around security infrastructure itself.
Firewalls, VPN gateways, identity appliances, and central management systems are attractive targets because organisations deliberately position them at high-trust boundaries. They can have broad visibility, privileged administrative functions, and access to traffic or policy information that ordinary servers do not possess.
That architectural role changes incident response once exploitation is confirmed. Installing a patch closes the known vulnerability, but it does not establish that an exposed system was never compromised before remediation.
Check Point has advised customers to review logs for anomalous certificate-based Mobile Access logins and suspicious follow-on activity related to CVE-2026-85102. It has also published separate hunting and remediation material for CVE-2026-93616.
The company says customers that installed the CVE-2026-85102 fix are protected against that vulnerability. The compromise question is most acute for organisations that remained exposed while exploitation attempts were occurring.
The sequence shows how quickly vulnerability status can change. A flaw can move from no known exploitation to confirmed attack activity within days, altering what organisations need to establish about systems that were exposed during the intervening period.
Where the affected product is part of the security control plane, the question is not only whether it has now been updated but whether it can still be trusted.





