Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day (CVE-2026-93616) Actively Exploited

Check Point Security Gateway VPN Pre-Auth RCE (TL-2026-2677) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-26. It has no confirmed attribution, affects Check Point Quantum Security Gateway, references 2 CVEs (CVE-2026-85102, CVE-2026-93616), maps to 9 MITRE ATT&CK techniques (T1018, T1036.005, T1046), and is covered by 9 detection rules and 9 indicators of compromise.

Key facts for TL-2026-2677

Threat ID
TL-2026-2677
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-26
Last reviewed
2026-09-26
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
smallbusiness
Detection rules
9
Indicators of compromise
9

Check Point confirmed active exploitation of two pre-authentication, unauthenticated CVSS 9.8 vulnerabilities: CVE-2026-85102, an improper-certificate-validation RCE in Security Gateway/Spark VPN negotiation exploited against Spark firewall customers since September 12, 2026; and CVE-2026-93616, a path-traversal/file-upload flaw in the Management web service exploited as a zero-day since July 23, 2026. Both were added to the CISA KEV catalog on September 22, 2026 with a September 25, 2026 federal remediation deadline.

How Check Point Security Gateway VPN Pre-Auth RCE works

Check Point disclosed and patched CVE-2026-85102 and a companion ASN.1 heap-overflow certificate-parsing bug, CVE-2026-85103, on September 9, 2026, reporting no evidence of exploitation at the time. CVE-2026-85102 stems from improper validation of certificate data/trust presented during VPN negotiation on Security Gateway and Spark Firewall devices configured for Site-to-Site or Remote Access VPN, allowing an unauthenticated remote attacker to bypass certificate trust checks during VPN/Mobile Access login and achieve arbitrary code execution on the gateway. On September 10, 2026 the Dutch National Cyber Security Centre (NCSC) warned that exploitation appeared imminent, and on September 12, 2026 Check Point observed a wave of exploitation attempts against Spark (SMB-focused firewall line) customers. The attempts originated from anonymization infrastructure -- commercial VPN services and proxies -- used to conceal the attackers' true source, and employed VPN client certificates bearing subject names crafted to resemble legitimate VPN users (CN=vpn,OU=users,O=global; CN=vpn-user,OU=users,O=global; CN=vpnuser,OU=users,O=global), with Check Point noting the list of observed subjects is not exhaustive. Following successful authentication-bypass, Check Point's hunting guidance directs defenders to look for internal port and service scanning originating from the resulting Mobile Access sessions, indicating post-exploitation reconnaissance.

Separately, on September 22, 2026 Check Point disclosed CVE-2026-93616, a pre-authentication path traversal and unsafe file-upload vulnerability in the Check Point Management web service (listening on TCP/19009) affecting Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. The flaw allows an unauthenticated attacker with network access to the management service to write attacker-controlled files to arbitrary filesystem locations outside the intended upload directory, then execute an uploaded script or load an arbitrary Java class -- achieving full code execution on the management plane without any credentials. Check Point stated it is aware this flaw was exploited as a zero-day beginning July 23, 2026 against "a handful of customers," roughly two months before public disclosure and patch availability; the company did not name the victims, the attackers, or what the attackers did with access after exploitation. Standard LivePatch updates do not remediate CVE-2026-93616 -- a Jumbo Hotfix or the R82.20 Security Hotfix is required.

Both vulnerabilities carry a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflecting network-exploitable, low-complexity, no-privilege, no-interaction attacks with high confidentiality/integrity/availability impact. CISA added both to the Known Exploited Vulnerabilities catalog on September 22, 2026 and set a September 25, 2026 remediation deadline for federal agencies under BOD 22-01/26-04. No threat-actor attribution, named campaign, or specific victim sector/region has been publicly disclosed for either vulnerability; the compromise of internet-facing VPN and management-plane infrastructure is consistent with both opportunistic mass exploitation and targeted initial-access operations, but no source confirms which applies here.

MITRE ATT&CK techniques used in TL-2026-2677

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery

Defense Evasion

T1036.005 Masquerading: Match Legitimate Resource Name or Location

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1090.003 Proxy: Multi-hop Proxy

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Persistence

T1505.003 Server Software Component: Web Shell

Reconnaissance

T1595 Active Scanning

Affected products and versions in Check Point Security Gateway VPN Pre-Auth RCE

  • Check Point — Quantum Security Gateway
    Vulnerable versions: R81 (EOS); R81.10 (Jumbo Hotfix Take 189 or below); R81.20 (Jumbo Hotfix Take 165 or below); R82 (Jumbo Hotfix Take 125 or below); R82.10 (Jumbo Hotfix Take 43 or below)
    Fixed in: LivePatch Take 26 (R81.20/R82/R82.10); R81.20 Jumbo Hotfix Take 166; R82 Jumbo Hotfix Take 126; R82.10 Jumbo Hotfix Take 44; R81.10 Jumbo Hotfix Take 190
  • Check Point — Spark Firewall (locally and centrally managed)
    Vulnerable versions: builds prior to fixed release
    Fixed in: R82.00.10 Build 2325; R81.10.17 Build 4968
  • Check Point — Security Management Server / Multi-Domain Security Management Server / Log Server / Multi-Domain Log Server / SmartEvent
    Vulnerable versions: R82.20 (without Security Hotfix); R82.10 (Jumbo Hotfix Take 44 or below); R82 (Jumbo Hotfix Take 126 or below); R81.20 (Jumbo Hotfix Take 169 or below); R81.10 (Jumbo Hotfix Take 191 or below); R81; R80.40; R80.30; R80.20; R80.10
    Fixed in: R82.20 Security Hotfix; R82.10 Jumbo Hotfix Take 45; R82 Jumbo Hotfix Take 127; R81.20 Jumbo Hotfix Take 170; R81.10 Jumbo Hotfix Take 192

Remediation for Check Point Security Gateway VPN Pre-Auth RCE

Patches

  • LivePatch Take 26 (R81.20, R82, R82.10) -- CVE-2026-85102 / CVE-2026-85103
  • Jumbo Hotfix R81.20 Take 166 / R82 Take 126 / R82.10 Take 44 / R81.10 Take 190 -- CVE-2026-85102 / CVE-2026-85103
  • Spark Firewall R82.00.10 Build 2325 / R81.10.17 Build 4968 -- CVE-2026-85102
  • R82.20 Security Hotfix; Jumbo Hotfix R82.10 Take 45 / R82 Take 127 / R81.20 Take 170 / R81.10 Take 192 -- CVE-2026-93616

Immediate actions

  • Apply Check Point LivePatch Take 26 on R81.20/R82/R82.10 Security Gateways to remediate CVE-2026-85102
  • Install the applicable Jumbo Hotfix (R81.20 Take 166, R82 Take 126, R82.10 Take 44, or R81.10 Take 190) if LivePatch cannot be applied, to remediate CVE-2026-85102
  • Update Spark Firewalls (locally and centrally managed) to R82.00.10 Build 2325 or R81.10.17 Build 4968
  • Apply the R82.20 Security Hotfix, or Jumbo Hotfix R82.10 Take 45 / R82 Take 127 / R81.20 Take 170 / R81.10 Take 192, to Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent to remediate CVE-2026-93616 -- standard LivePatch does not fix this CVE
  • Hunt Mobile Access / Remote Access VPN authentication logs for the published certificate subjects (CN=vpn,OU=users,O=global; CN=vpn-user,OU=users,O=global; CN=vpnuser,OU=users,O=global) and for any anomalous certificate-based logins with unrecognized subject names
  • Review Check Point support articles sk1000117 (CVE-2026-85102) and sk1000171 (CVE-2026-93616) for vendor-provided hunting guidance and indicators of compromise

Workarounds

  • Disable VPN implied rules and create explicit firewall rules restricting Site-to-Site VPN (UDP/500, UDP/4500) to specific, known peer IP addresses
  • Restrict network access to the Management web service (TCP/19009) to trusted administrator IP addresses when the Security/Jumbo Hotfix for CVE-2026-93616 cannot be applied immediately

Longer-term hardening

  • Remove direct internet exposure of Check Point Management Server / TCP-19009 web services; place management interfaces behind a Security Gateway or dedicated management network with access restricted to trusted administrator IP ranges
  • Establish continuous patch-compliance tracking across all deployed Security Gateway, Spark, and Security Management Server instances given the two-month unpatched exposure window observed for CVE-2026-93616
  • Deploy detection content for post-authentication-bypass behavior on VPN gateways, including internal network/port scanning originating from newly established Mobile Access sessions

CVEs associated with Check Point Security Gateway VPN Pre-Auth RCE

CVE-2026-85102, CVE-2026-93616

Weaknesses (CWE) in Check Point Security Gateway VPN Pre-Auth RCE

CWE-295, CWE-22

Timeline of Check Point Security Gateway VPN Pre-Auth RCE

  • Check Point later confirms CVE-2026-93616 exploitation began against a handful of Management Server customers as an undisclosed zero-day.
  • The Canadian Centre for Cyber Security publishes an advisory on the newly disclosed Check Point VPN certificate vulnerabilities.
  • Check Point discloses and patches CVE-2026-85102 and companion flaw CVE-2026-85103 (VPN certificate handling), begins LivePatch rollout; reports no evidence of exploitation at time of disclosure.
  • Dutch National Cyber Security Centre (NCSC) alerts on the Security Gateway VPN certificate issue and warns that imminent exploitation is expected.
  • Check Point observes a wave of exploitation attempts against CVE-2026-85102 targeting Spark firewall customers, originating from anonymization VPN services and proxies using spoofed VPN-user certificate identities.
  • CISA adds both CVE-2026-85102 and CVE-2026-93616 to the Known Exploited Vulnerabilities (KEV) catalog.
  • Check Point publicly discloses CVE-2026-93616 (Management web service path traversal), releases the R82.20 Security Hotfix and Jumbo Hotfixes, and publishes hunting guidance/IOCs in support article sk1000171.
  • Check Point publishes a combined 'Action Required' security advisory confirming active exploitation of both CVE-2026-85102 and CVE-2026-93616; coverage follows from BleepingComputer, SecurityWeek, Help Net Security, and others.
  • CISA's BOD 26-04 remediation deadline for federal agencies to mitigate CVE-2026-85102 and CVE-2026-93616 takes effect.

Sources cited for Check Point Security Gateway VPN Pre-Auth RCE

More in vulnerability

Detection coverage for TL-2026-2677

As of 2026-09-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2677 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats