Two Critical Check Point Flaws Are Being Actively Exploited and Federal Agencies Had Three Days to Patch
CISA added both vulnerabilities to its must-patch list on September 22, with a September 25 deadline for US government networks. One was a zero-day. The other had already been quietly targeted in the wild.

Key points
- CVE-2026-93616, a critical flaw in Check Point's Management Server products, carries a CVSS score of 9.8 out of 10 and lets attackers upload and run malicious code without a password.
- A second flaw, CVE-2026-85102, also scoring 9.8, lets attackers exploit improper certificate validation in Check Point's VPN products to run code remotely without authentication.
- CISA added both bugs to its Known Exploited Vulnerabilities catalogue on September 22, 2026, ordering US federal agencies to patch by September 25.
- Check Point confirmed a handful of customers were attacked via CVE-2026-93616 before a fix existed, making it a zero-day: a flaw used against real targets before the vendor issued a patch.
- Standard LivePatch updates do not fix CVE-2026-93616, so admins who assumed automatic updates had them covered should verify.
What do these flaws actually do?
Both bugs score 9.8 out of 10 on the CVSS scale, a standardised system that measures exploitability and potential damage. That close to the maximum means no password is needed and no special foothold on the network is required.
CVE-2026-93616 is a path traversal and file upload vulnerability. An attacker can trick the server into accepting a malicious file from anywhere on the internet, then make the server run it. Affected products include Check Point's Security Management Server, Multi-Domain Security Management Server, Log Server and SmartEvent. These are the control-plane products security teams use to manage firewall rules across an entire organisation, so whoever controls them can see and change the rules protecting the whole network. We first reported on exploited Check Point authentication weaknesses in a 21 September story on CVE-2026-91843, the third critical bug in a fortnight for the company at that point.
CVE-2026-85102 sits inside the VPN, the encrypted tunnel remote workers use to connect to company systems. The flaw stems from the Gateway not properly validating the identity certificates exchanged during a VPN connection. A criminal exploiting it could impersonate a trusted connection and run arbitrary code on the Gateway. Check Point's Security Gateway and Spark Firewall products running Site-to-Site or Remote Access VPN are affected.
How serious is the real-world threat?
Both bugs are already being used against real targets. That's the threshold CISA applies before adding a flaw to its Known Exploited Vulnerabilities catalogue.
For CVE-2026-93616, Check Point confirmed active exploitation before the patch shipped. Organisations running unpatched Management Servers were exposed with no official fix available. The number of confirmed victims is described as small, but Check Point also released indicators of compromise, technical fingerprints defenders can use to check whether their systems were already hit.
CVE-2026-85102 was patched on September 9, two weeks before CISA's catalogue entry. Check Point had no evidence of exploitation at that point. By September 22 the company was seeing active attempts against Spark customers globally. The pattern here is familiar: a two-week gap between patch and confirmed exploitation is short enough that any organisation slow to apply firewall fixes is playing a losing game.
What should organisations do right now?
Patch first. For CVE-2026-93616, Check Point released the R82.20 Security Hotfix and included fixes in Jumbo Hotfix Accumulator versions R82.10 Take 45, R82 Take 127, R81.20 Take 170 and R81.10 Take 192. Standard LivePatch updates don't cover this flaw.
If patching immediately isn't possible, Check Point advises blocking TCP port 19009 at the network edge and restricting Management Server access to trusted IP addresses. For CVE-2026-85102, the fix has been available since September 9; any organisation still running an unfixed Gateway should treat this as an emergency.
Regular employees aren't expected to act directly. But anyone whose employer uses Check Point products should be alert to unexpected password-reset requests or unusual access warnings in the coming weeks, as those can signal a network was accessed before patches were applied.
The uncomfortable truth is that management-plane software, the systems that govern other security tools, is precisely where an unauthenticated critical bug does the most damage. When the control plane and the VPN gateway are both in play at once, the window for a complete network takeover is very short.



