Check Point released emergency fixes for two actively exploited critical vulnerabilities: CVE-2026-93616 (CVSS 9.8), affecting network-security management products, and CVE-2026-85102, affecting Security Gateway Spark Firewall devices. The management-server flaw allows an unauthenticated attacker to upload and execute arbitrary scripts, while the VPN certificate-validation flaw can enable authentication bypass and remote code execution during VPN negotiation. Check Point published indicators of compromise, patches, and risk-mitigation guidance.
CISA added both Check Point flaws to its Known Exploited Vulnerabilities catalog alongside exploited issues in Arista VeloCloud Orchestrator and F5 BIG-IP Access Policy Manager. U.S. federal civilian agencies were directed to remediate all four cataloged vulnerabilities by September 25, 2026; organizations using affected Check Point management servers or Spark gateways should prioritize patching, review published IoCs, and investigate systems for evidence of compromise.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
CISA added Check Point CVE-2026-85102 and CVE-2026-93616, Arista VeloCloud Orchestrator CVE-2026-93952, and F5 BIG-IP APM CVE-2026-94127 to its Known Exploited Vulnerabilities catalog. It directed U.S. federal civilian executive branch agencies to remediate all four by September 25, 2026.
F5 disclosed CVE-2026-94127, a heap-based buffer overflow in BIG-IP Access Policy Manager configurations acting as an OAuth Authorization Server, and confirmed exploitation had been observed. The flaw can enable unauthenticated arbitrary code execution.
Check Point issued advisories sk1000117 and sk1000118 for its vulnerabilities and corrected the CVE-2026-85102 VPN certificate-validation flaw. The flaw could allow unauthenticated attackers to bypass authentication checks and execute code on affected gateways.
The Dutch NCSC warned that CVE-2026-85102 could soon be actively exploited. The vulnerability affects Check Point VPN negotiation and permits authentication bypass and potential code execution.
Exploitation attempts targeting Check Point Spark Firewall customers were observed globally for CVE-2026-85102. The vulnerability stems from improper certificate-data validation during VPN negotiation.
Check Point confirmed that CVE-2026-93616, a CVSS 9.8 path-traversal and file-upload flaw in Security Management Server-related products, had been exploited against a limited number of customers. The company released an R82.20 Security Hotfix and other Jumbo Hotfix updates, and published indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.