Check Point Confirms Two Maximum-Severity Flaws Are Being Exploited in the Wild
Published on 09/26/2026 at 17:30 | Editorial boerse-global.de
Attackers are actively exploiting a pair of critical vulnerabilities in Check Point's security products, both rated 9.8 out of 10 on the CVSS severity scale, the vendor has confirmed.
The more recently disclosed flaw, tracked as CVE-2026-85102, affects the company's VPN gateways. Because it can be triggered without any prior authentication, an outside actor who reaches the device over the network could seize full control of the gateway and run arbitrary code on it — a scenario that puts an organisation's entire network integrity at risk. Check Point shipped a fix on 9 September 2026, and the first attacks against Spark firewalls were observed three days later, on 12 September 2026.
Which products are exposed
Quantum Security Gateways are in scope, along with Spark firewalls, provided Site-to-Site VPN or Remote Access VPN is switched on. According to the vendor, the vulnerable gateway releases are R81, R81.10, R81.20, R82 and R82.10, with Spark firewalls also affected. The 9.8 score is calculated under CVSS v3.1.
A second flaw, CVE-2026-93616, carries the same 9.8 rating but targets a different part of the stack: Check Point's management, logging and SmartEvent products. Check Point says this one has been exploited as a zero-day since 23 July 2026. Through that vector, intruders can upload and execute their own scripts on management systems. Compromising the management and logging layer is especially dangerous, since it can hand attackers sweeping control over the whole monitored network infrastructure.
Washington sets a deadline
The US Cybersecurity and Infrastructure Security Agency treated the situation as urgent, adding both CVE-2026-85102 and CVE-2026-93616 to its catalogue of known exploited vulnerabilities on 22 September 2026. CISA's assessment is that either flaw can be exploited remotely without credentials. Civilian federal agencies in the United States were given a binding deadline of 25 September 2026 to remediate both.
Check Point's guidance to administrators is to patch gateways and management environments separately, using the updates provided for each. Log files, meanwhile, should be examined closely for signs of suspicious activity.
CISA's advice to affected organisations goes beyond simply installing the updates without delay: exposed systems should also undergo a thorough forensic review, so that any access that has already occurred can be uncovered in time.
