Skip to content
CVEvulnerabilityVulnerability Research

Patch now: Check Point Security Gateway RCE (CVE-2026-85102) has a federal deadline today

3 min read
Share

Patch now: Check Point Security Gateway RCE (CVE-2026-85102) has a federal deadline today

If you run Check Point Security Gateway or Security Management Server and you have not applied the September 9 patch, today is your last day before FCEB agencies hit the mandatory remediation deadline. This post explains what the vulnerability does, what attackers are doing with it, and what to do right now.

What the vulnerability is

CVE-2026-85102 is a pre-authentication remote code execution flaw in Check Point Security Gateway's VPN certificate-handling routine. CVSS 9.8. An unauthenticated remote attacker sends a crafted certificate during VPN negotiation, bypasses validation, and executes arbitrary code on the gateway. No credentials required.

CVE-2026-93616 is a companion path traversal flaw in Check Point Security Management Server. CVSS 9.1. It lets unauthenticated attackers read files outside the intended directory, including configuration data and credentials stored on the management plane.

Both were patched on September 9, 2026. Both were added to the CISA Known Exploited Vulnerabilities catalog on September 22 with a three-day federal remediation deadline, which expires today, September 25.

What attackers are doing

Check Point observed exploitation beginning September 12, about 72 hours after the patch release. The primary targets have been Spark VPN customers. The attack chain on CVE-2026-85102 is straightforward: send a malformed certificate to UDP/500 or UDP/4500, get code execution on the gateway, pivot to the internal network. Check Point's advisory and BleepingComputer's reporting both corroborate active in-the-wild exploitation.

SD-WAN orchestrator and VPN gateway compromises of this type are high-value targets. Once an attacker controls the gateway, they have a network-level vantage point for lateral movement and data exfiltration that bypasses most endpoint-based detections.

What to do right now

Check Point's recommended fix is LivePatch Take 26 for supported gateways. If you cannot apply the LivePatch, the Jumbo Hotfix builds are R82.00.10 Build 2325 or R81.10.17 Build 4968 or later. If patching is not immediately possible, the interim mitigation is to disable Site-to-Site VPN implied rules and create explicit rules that restrict VPN traffic on UDP/500 and UDP/4500 to specific peer IP addresses.

For CVE-2026-93616 on Security Management Server, apply the same Jumbo Hotfix build set. The management server should not be internet-facing in any case: if yours is, that is a higher-priority remediation than the patch itself.

FCEB agencies are required to remediate by today. Non-federal organizations should treat this as urgent regardless of the formal deadline.

The broader pattern

Certificate validation bypasses enabling pre-authentication RCE on network security appliances is a recurring vulnerability class. Fortinet, Palo Alto, Ivanti, and now Check Point have all had high-profile variants of this pattern in the past two years. The consistent lesson: perimeter security devices with internet-facing management or VPN interfaces are high-value targets and need prioritized patching cycles separate from general IT patch management cadence.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you want to talk through how to prioritize patch deployment for perimeter devices at scale.