Check Point Warns of Widespread Exploitation of Security Gateway VPN Flaw
Cybersecurity company Check Point has confirmed that hackers are actively exploiting a pair of pre-authentication vulnerabilities in its Security Gateway product, which enables secure remote access through virtual private networks (VPNs). The vulnerability, tracked as CVE-2026-85102, affects the certificate-handling functionality of the VPN and allows attackers to execute arbitrary code. A second flaw, identified as CVE-2026-93616, impacts the Management web service and permits script execution and Java class loading.
The Dutch Nationaal Cyber Security Centrum (NCSC) first alerted users to the issue on September 10, warning that imminent exploitation was expected due to the vulnerability’s severity. Check Point has since confirmed that malicious activity began on September 12, with attackers using VPNs and proxies to conceal their locations.
In a statement, Check Point revealed that it had observed a “wave of exploitation attempts” against Spark customers, which originated from anonymization infrastructure, including VPN services and proxies. The company noted that the attackers used certificates bearing specific subjects, but cautioned that this may not be an exhaustive list and additional subjects could be in use.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added both flaws to its Known Exploited Vulnerabilities catalog, urging federal agencies to apply available fixes and/or mitigations by September 25. Check Point recommends installing a specific LivePatch or updating the product to the latest fixed version to mitigate the risk. Alternatively, administrators can disable VPN implied rules and create explicit rules to restrict access.
The exploitation of these vulnerabilities is particularly concerning due to the potential for lateral movement within an organization’s network. Attackers could use the VPN flaw to gain initial access, followed by exploiting CVE-2026-93616 to elevate privileges and further compromise the system.
To protect against this threat, administrators should verify if LivePatch is active on their Security Gateway and ensure that all patches are up-to-date. If updating isn’t feasible, restricting access through explicit rules can provide a temporary mitigation measure. It’s essential for organizations using Check Point’s Security Gateway to prioritize patching and take immediate action to prevent potential exploitation.
In conclusion, the widespread exploitation of these vulnerabilities underscores the importance of maintaining vigilant cybersecurity practices and staying up-to-date with the latest security patches. Organizations should regularly review their systems’ vulnerability posture and implement robust mitigation measures to prevent such attacks in the future. By doing so, they can minimize the risk of falling victim to these types of exploits and protect sensitive data from unauthorized access.
Source: Bleeping Computer — 2026-09-23