Critical Check Point disclosures: CVE-2026-85102 and CVE-2026-93616 #

Check Point disclosed in two advisories that certain versions their products are affected by multiple vulnerabilities:

  • CVE-2026-85102: Improper certificate trust validation during VPN negotiation in Security Gateway, Spark Firewall (Centrally Managed and Locally Managed) allows an unauthenticated, remote attacker to execute arbitrary code on the gateway. A fix has been available since September 9, 2026, but exploitation attempts targeting Spark Firewall customers have since been observed. The vulnerability has been designated CVE-2026-85102 and has been rated critical with a CVSS score of 9.8.
  • CVE-2026-93616: A pre-authentication directory traversal and file upload vulnerability in the Check Point Management web service (Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent) allows an unauthenticated attacker to upload a script to an arbitrary path, execute it, and load an arbitrary Java class. The vulnerability has been designated CVE-2026-93616 and has been rated critical with a CVSS score of 9.8.

Evidence indicates that both vulnerabilities are actively exploited in the wild, leading to their addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026.

    The following versions are affected

    • Security Gateway: R81.20, R82, R82.10, and End-of-Support (EOS) versions R80 through R81.10 (affected by CVE-2026-85102).
    • Spark Firewall (Centrally Managed and Locally Managed): R82.00.X prior to R82.00.10 Build 2325, and R81.10.X prior to R81.10.17 Build 4968 (affected by CVE-2026-85102).
    • Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent: R82.20 with no Jumbo Hotfix, R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, and End-of-Support (EOS) versions R81.10 with Jumbo Hotfix Take 190 or below through R80 (affected by CVE-2026-93616).

        What are Check Point Security Gateways, Spark Firewalls, Security Management Server, and Multi-Domain Security Management? #

        Check Point Security Gateways act as physical or virtual enforcement points that inspect network traffic and execute access rules in real time. Spark Firewalls are compact, enterprise-grade appliances designed to extend these security controls to small-to-medium businesses and remote branch offices. The Security Management Server serves as the centralized database and control plane that stores configuration settings, processes logs, compiles security policies, and deploys them to those gateways. Multi-Domain Security Management (MDS) extends this architecture by hosting multiple, isolated virtual management servers on a single platform.

        What is the impact? #

        Successful exploitation of these vulnerabilities would allow an unauthenticated remote attacker to achieve full, arbitrary code execution across affected security gateways and central management infrastructure, resulting in complete system compromise and potential full network takeover.

        Are updates or workarounds available? #

        Users are encouraged to update to the latest version as quickly as possible:

        • Security Gateway: Install Check Point LivePatch Take 26 for an immediate fix (applied automatically if automatic LivePatch installation is enabled), or upgrade to R82.10 Jumbo Hotfix Take 44 or later, R82 Take 126 or later, R81.20 Take 166 or later, or End-of-Support (EOS) R81.10 Take 190 or later to resolve CVE-2026-85102.
        • Spark Firewall (Centrally Managed and Locally Managed): Upgrade to R82.00.10 Build 2325 or later, or R81.10.17 Build 4968 or later, to resolve CVE-2026-85102.
        • Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent: Upgrade to R82.20 Security Hotfix Take 1, R82.10 Jumbo Hotfix Take 45 or later, R82 Jumbo Hotfix Take 127 or later, R81.20 Jumbo Hotfix Take 170 or later, or R81.10 Jumbo Hotfix Take 192 or later, to resolve CVE-2026-93616.

        Notes:

        • Check Point LivePatch Take 28/29 does not resolve CVE-2026-93616; the Jumbo Hotfix upgrades listed above are required.
        • Customers who installed the offline LivePatch package while running R82.10 Jumbo Hotfix Take 24 or lower, R82 Take 107 or lower, or R81.20 Take 146 or lower must reinstall Check Point LivePatch Take 26 to ensure full protection against CVE-2026-85102.

        Mitigation:

        • Restrict Trusted Clients (GUI clients) access strictly to trusted IP addresses or subnets.
        • Protect management interfaces with a firewall and restrict access exclusively to authorized IP addresses.

          Finding exposed Check Point systems with runZero #

          From the Asset Inventory, use the following query to locate potentially impacted assets:

          os:="Check Point Gaia"

          July 2026: CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145 #

          Check Point disclosed in three advisories that certain versions their products are affected by multiple vulnerabilities:

          • CVE-2026-16232: An authentication bypass vulnerability in the SmartConsole login process that allows a remote, unauthenticated attacker to obtain an application login token and authenticate with full administrative privileges. To exploit this, the attacker must have network access to the management interface, and the system must lack Trusted Clients (GUI clients) restrictions. Successful exploitation permits full modification of security policies and configurations. The vulnerability has been designated CVE-2026-16232 and has been rated critical with a CVSS score of 9.1.
          • CVE-2026-62144: An authentication bypass vulnerability in the Security Management and Multi-Domain Security Management servers that allows a remote, unauthenticated attacker to execute administrative commands on the server, including run-script and exec-command on managed Security Gateways. The attacker must have access to the management interface, and the system must lack firewall protections or Trusted Clients restrictions. The vulnerability has been designated CVE-2026-62144 and has been rated critical with a CVSS score of 9.1.
          • CVE-2026-62145: A local privilege escalation vulnerability in the Gaia Portal that allows an authenticated, low-privileged (read-only) attacker to execute arbitrary commands with root privileges. The vulnerability has been designated CVE-2026-62145 and has been rated high with a CVSS score of 7.5.

          There is evidence that CVE-2026-16232 is being actively exploited in the wild, prompting its addition to the CISA KEV catalog on July 22, 2026

            The following versions are affected

            • Security Management Server, Multi-Domain Security Management Server (MDS), Security Gateways: R81.20, R82, R82.10, and End-of-Support (EOS) versions R77.30 through R81.10.

            Note: Spark Gateways are not affected.

            What is the impact? #

            Successful exploitation of these vulnerabilities would allow an attacker to bypass authentication to gain full administrative control over management servers, execute arbitrary commands on managed firewalls, and escalate local privileges to root.

            Are updates or workarounds available? #

            Users are encouraged to update to the latest version as quickly as possible:

            • R82.10: Upgrade to Jumbo Hotfix Accumulator Take 36 or later.
            • R82: Upgrade to Jumbo Hotfix Accumulator Take 118 or later.
            • R81.20: Upgrade to Jumbo Hotfix Accumulator Take 158 or later.
            • End-of-Support (EOS) Releases (R81.10, R81, R80.40, R80.30, R80.20, R80.10, R80, and R77.30): No hotfix specified. Upgrade to a supported release or apply vendor mitigations.

            Mitigation:

            • Restrict Trusted Clients (GUI clients) access strictly to trusted IP addresses or subnets.
            • Protect management interfaces with a firewall and restrict access exclusively to authorized IP addresses.

              How to find potentially vulnerable systems with runZero #

              From the Asset Inventory, use the following query to locate potentially impacted assets:

              os:="Check Point Gaia"

              June 2026: CVE-2026-50751 #

              Check Point disclosed that certain versions of their VPN products utilize the deprecated IKE protocol version 1 (IKEv1) that are affected by an authentication logic flow vulnerability. Remote unauthenticated attackers can utilize this vulnerability to bypass the authentication validation without credentials in order to gain access to secure networks. This vulnerability has been designated CVE-2026-50751 and has been rated critical with a CVSS score of 9.3.

                The following versions are affected:

                  • Security Gateways:
                    • R82.10 Jumbo Hotfix Take 19 or below
                    • R82 Jumbo Hotfix Take 103 or below
                    • R81.20 Jumbo Hotfix Take 141 or below
                    • R81.10 (End-of-Support (EOS))
                    • R81 (End-of-Support (EOS))
                    • R80.40 (End-of-Support (EOS))
                  • Spark Firewalls: 
                    • R80.20.X (End-of-Support (EOS))
                    • R82.00.X
                    • R81.10.X

                    What is Check Point Remote Access and Mobile Access VPN? #

                    Check Point Remote Access and Mobile Access VPN provide users access to corporate networks over IPSec.

                    What is the impact? #

                    Successful exploitation of the vulnerability would allow an attacker to establish an unauthorized VPN connection and gain access to protected networks.

                    Are updates or workarounds available? #

                    Users are encouraged upgrade affected systems to the following versions:

                    Security Gateway, Maestro Orchestrator, and Security Group

                    • R82.10 Jumbo Hotfix Accumulator Take 19 (Take #3)
                    • R82.10 Jumbo Hotfix Accumulator Take 6 (Take #2)
                    • R82 Jumbo Hotfix Accumulator Take 103 (Take #2)
                    • R82 Jumbo Hotfix Accumulator Take 91 (Take #2)
                    • R81.20 Jumbo Hotfix Accumulator Take 141 (Take #2)
                    • R81.20 Jumbo Hotfix Accumulator Take 127 (Take #2)
                    • R81.20 Jumbo Hotfix Accumulator Take 120 (Take #2)
                    • R81.20 Jumbo Hotfix Accumulator Take 113 (Take #2)

                    Spark Firewall Appliances

                    • R82.00.10 Build 998002216

                    For End-of-Support products Check Point has provided multiple mitigation options.

                      How to find potentially vulnerable systems with runZero #

                      From the Service inventory, use the following query to locate potentially impacted assets:

                      hw:="Check Point%" AND protocol:ike AND ike.version:="1.0"

                      May 2024: CVE-2024-24919 #

                      On May 28, 2024, Check Point disclosed a serious vulnerability in Check Point Security Gateway Devices with certain remote access software blades (security modules) enabled. Per their guidance, devices are impacted if one of the following conditions are met:

                      • The IPsec VPN Blade is enabled, but ONLY when included in the Remote Access VPN community.
                      • The Mobile Access Software Blade is enabled.

                      The issue, identified as CVE-2024-24919, allows reading arbitrary files on the targeted appliance by unauthenticated remote attackers. This vulnerability could be leveraged to read sensitive files such as those containing password hashes, certificates, and ssh keys.

                      This vulnerability has a CVSS score of 8.6 out of 10, indicating that this is a high risk vulnerability. According to their disclosure and information provided by CISA this vulnerability is being actively exploited. A report from mnemonic.io states that they have observed attacks at least as far back as April 30, 2024.

                      What is the impact? #

                      Upon successful exploitation of the vulnerability, unauthenticated remote attackers could access password hashes for local users. If the hashes are cracked the attacker may be able to log into these user accounts if secondary controls, such as MFA, are not enforced. This includes service accounts that may be used to access Active Directory or other services. Attackers could leverage this information to move across a target's network. 

                      Are updates or workarounds available? #

                      Check Point has released a software updates to address this vulnerability. They also provide guidance for other measures that should be taken after the vulnerability has been addressed. These can be found in their advisory.

                      How do I find potentially vulnerable Check Point devices with runZero? #

                      From the Asset Inventory, use the following query to locate assets that may be running the vulnerable operating system in your network:

                      hardware:"Check Point" AND (_service.last.http.body:"Check Point Mobile" OR _service.http.body:"Check Point Mobile" OR udp_port:500)

                      Written by Cale Black

                      Cale Black is a vulnerability researcher at runZero. Previously Cale worked as a lead penetration tester and researcher where he reproduced and delivered over 200 N-day exploits, and developed for the go-exploit exploitation framework.

                      More about Cale Black

                      Written by Tom Sellers

                      Tom Sellers is a Principal Research Engineer at runZero. In his 25 years in IT and Security he has built, broken, and defended networks for companies in the finance, service provider, and security software industries. He has built and operated Internet scale scanning and honeypot projects. He is credited on many patents for network deception techonology. A strong believer in Open Source he has contributed to projects such as Nmap, Metasploit, and Recog.

                      More about Tom Sellers

                      Written by Matthew Kienow

                      Matthew Kienow is a software engineer and security researcher. Matthew previously worked on the Recog recognition framework, AttackerKB as well as Metasploit's MSF 5 APIs. He has also designed, built, and successfully deployed many secure software solutions; however, often he enjoys breaking them instead. He has presented his research at various security conferences including DerbyCon, Hack In Paris, and CarolinaCon. His research has been cited by CSO, Threatpost and SC Magazine.

                      More about Matthew Kienow
                      Subscribe Now

                      Get the latest news and expert insights delivered in your inbox.

                      Welcome to the club! Your subscription to our newsletter is successful.

                      Explore more runZero

                      Product
                      runZero 5.1 is here: Secure AI workflows, enhanced integrations, and expanded autonomous discovery
                      runZero 5.1 takes on the heavy lifting across five key areas, enabling you to unmask and remediate exposures with less friction and more speed.
                      Podcasts
                      Know Your Adversary with HD Moore
                      runZero CEO HD Moore breaks down the myth of air-gapped networks, the impact of AI on security, and why asset connectivity is everything.
                      runZero Perspective
                      BOD 26-04: A new era of prioritized remediation
                      A complete breakdown of CISA's BOD 26-04 directive. Learn how the shift to SSVC, risk-based KEV prioritization, and 3-day remediation impacts your...
                      runZero Perspective
                      Dawn of the apex agentic adversary
                      When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
                      Webcasts
                      runZero Hour, Ep. 34: Vulnerability vibes: Disclosures, meetups, and the AI evolution
                      Watch the runZero Hour replay: separating AI "slop" from real vulnerability insights, running local hacker meetups, and analyzing the top monthly...
                      Product Videos
                      Custom integrations at AI speed
                      Build custom exposure management integrations on your terms. runZero 5.1 lets you leverage your choice of AI to create, adapt, and secure your...
                      Webcasts
                      runZero Hour, Ep. 33: Hacker Summer Camp: we survived the Vegas heat (and the bugs)
                      In this post-Hacker Summer Camp recap, the runZero team break down the research, tools, and trends discussed at BSides Las Vegas, Black Hat and DEF...
                      Podcasts
                      The Internet's biggest point of failure
                      Join Tod Beardsley on Secure & Scale as he explores the future of vulnerability management, CVE fragmentation, and how AI is changing security...

                      See Results in Minutes

                      See & secure your total attack surface. Even the unknowns & unmanageable.