GBHackers

Hackers Exploit Check Point VPN RCE and Management Zero-Day in Attacks


Check Point has warned customers about the active exploitation of two critical vulnerabilities in its VPN gateway and Security Management products: CVE-2026-85102 and the newly disclosed CVE-2026-93616.

Both vulnerabilities have a CVSS score of 9.8 and allow for pre-authentication attacks, making immediate patching and reducing exposure essential.

Check Point Flaws

CVE-2026-85102 is an improper certificate-validation vulnerability affecting Check Point Security Gateway and Spark Firewall VPN deployments. This flaw allows an unauthenticated remote attacker to execute arbitrary code during VPN negotiation, including in Remote Access and certificate-enabled Site-to-Site VPN configurations.

Check Point released a fix on September 9; however, they subsequently identified exploitation attempts against Spark Firewalls starting September 12.

The attacks reportedly originated from anonymization infrastructure, including VPN services and proxy networks. Check Point observed malicious certificates with subject names such as CN=vpn, OU=users, O=global, CN=vpn-user, OU=users, O=global, and CN=vpnuser, OU=users, O=global.

The vendor emphasizes that these indicators are not exhaustive, and defenders should investigate any anomalous certificate-based Mobile Access logins, regardless of the certificate subject.

Affected VPN products include Security Gateway and centrally or locally managed Spark Firewall devices running versions R81 through R82.10, including several end-of-support releases.

Version R82.20 is not affected by CVE-2026-85102. The fix is available through Check Point LivePatch Take 26, specific Jumbo Hotfix Accumulators, and updated Spark Firewall builds.

The second flaw, CVE-2026-93616, is a pre-authentication directory traversal and file upload vulnerability in Check Point Management web services.

This vulnerability enables an unauthenticated attacker to upload and execute arbitrary scripts on a compromised Management Server. Check Point has reported observing a limited number of targeted attacks in the wild.

This issue affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent installations. However, Smart-1 Cloud, Check Point Firewall Appliances, and Spark Firewalls are not affected by this vulnerability.

Affected versions include R82.20, R82.10 with Jumbo Hotfix Take 44 or earlier, R82 with Take 126 or earlier, R81.20 with Take 166 or earlier, and older end-of-support releases.

Unlike the VPN vulnerability, LivePatch Take 28/29 does not remediate CVE-2026-93616, as Check Point stated that a LivePatch is unavailable due to the nature of the fix.

Organizations should prioritize the following actions:

  • Immediately apply the available security hotfixes or updated Jumbo Hotfix Accumulators.
  • Restrict access to the Security Management Server behind a Check Point gateway or firewall.
  • Limit access to TCP/19009 strictly to trusted IP addresses.
  • 4. Review Mobile Access and VPN logs for suspicious certificate-authentication events and any subsequent internal port or service scanning.
  • 5. Look for unusually long usernames in `cpm.elg` logs, analyze associated FWM/MDS core dumps, and monitor for errors containing directory traversal sequences such as ../.

These two vulnerabilities underscore the heightened risk posed by internet-exposed VPN and management infrastructure. Organizations that have delayed patching should treat both issues as incident-response priorities, especially when remote-access services or centralized security-management servers are accessible from the outside.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link