Security advisories

Actively Exploited Vulnerabilities in Check Point Security Gateway and Security Management (CVE-2026-93616 and CVE-2026-85102)

September 23, 2026

3 MINS READ

THE THREAT

On September 22nd, 2026, Check Point published a security advisory disclosing two critical vulnerabilities CVE-2026-93616 (CVSS: 9.8) and CVE-2026-85102 (CVSS: 9.8), affecting its Security Gateway and Security Management products. Both vulnerabilities are pre-authentication flaws, and Check Point has confirmed active exploitation in the wild.

Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to execute arbitrary code or scripts on affected systems, potentially leading to full compromise of the Security Gateway or Management Server. Fixes are available for both vulnerabilities.

As exploitation is ongoing, organizations running affected Check Point products are advised to apply the relevant patches immediately.

What We're Doing About It

What You Should Do About It

Additional Information

CVE-2026-93616 is a newly identified zero-day affecting the Check Point Security Management Server and related management products. Check Point has confirmed a small number of targeted attacks exploiting this flaw, with the earliest observed activity dating back to July 23rd, 2026. A fix for this flaw was released as part of this advisory on September 22nd, 2026.

CVE-2026-85102 affects Check Point Security Gateway and Spark Firewall products where Site-to-Site VPN or Remote Access VPN is in use. Check Point first disclosed and patched this vulnerability on September 9th, 2026, at which time there was no evidence of exploitation. Exploitation attempts were subsequently observed beginning September 12th, targeting Spark customers globally.

At the time of writing, technical details on the vulnerabilities are limited, and there is no publicly available Proof-of-Concept (PoC) exploit code. CISA added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of September 25th, 2026. Given that both vulnerabilities are confirmed to be actively exploited in the wild and have been added to CISA's KEV catalog, affected organizations should treat patching as an immediate priority.

Affected Products
Vulnerability Product Affected Version(s) Resolved Version(s)
CVE-2026-93616 Security Management, Multi-Domain Security Management, Log Server, SmartEvent R82.20; R82.10 (Take 44 or lower); R82 (Take 126 or lower); R81.20 (Take 166 or lower); R81.10 (Take 190 or lower); R80–R81 (all EoS) Per sk1000171
CVE-2026-85102 Security Gateway, Spark Firewall (Centrally & Locally Managed) R81.20, R82, R82.10, R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10 (all EoS), R81.10.x, R82.00.x Per sk1000117

References:
[1] https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
[2] https://support.checkpoint.com/results/sk/sk1000171/
[3] https://support.checkpoint.com/results/sk/sk1000117
[4] https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories