TTO-2026-0923-157 · September 23, 2026 Active ExploitationZero-DayFollow-Up

Check Point CVE-2026-85102 Active Exploitation Confirmed Against Spark Firewalls — New CVE-2026-93616 Management Zero-Day Since July — Updates TTO-2026-0913-123

checkpoint.comCVE-2026-85102 active exploitation confirmed Sep 12CVE-2026-93616 Management web service zero-day since July 23Spark firewall targetingAnonymization infrastructure usedCISA KEV September 25 deadline for bothUpdates TTO-2026-0913-123

Summary

Check Point has confirmed active exploitation of CVE-2026-85102, the pre-authentication VPN certificate RCE vulnerability in its Security Gateway products documented in TTO-2026-0913-123 as imminent-exploitation risk. Exploitation of Spark firewall customers began September 12, 2026, using anonymization infrastructure. Simultaneously, Check Point has disclosed CVE-2026-93616, a path traversal vulnerability in the Management web service component of Check Point Management Server that has been exploited as a zero-day since July 23, 2026 — a disclosure gap of more than 60 days. CISA has added both CVE-2026-85102 and CVE-2026-93616 to its Known Exploited Vulnerabilities catalog with a September 25, 2026 federal remediation deadline.

Timeline

DateEvent
July 23, 2026CVE-2026-93616 first exploited as zero-day against Check Point Management Server customers; not yet publicly disclosed
Sep 9-10, 2026Check Point patches CVE-2026-85102 and CVE-2026-85103; Dutch NCSC warns exploitation imminent; TTO-2026-0913-123 published
Sep 12, 2026Wave of exploitation attempts against Spark customers using CVE-2026-85102; originates from anonymization infrastructure
Sep 22-23, 2026Check Point publicly discloses CVE-2026-93616 and confirms active exploitation of CVE-2026-85102; CISA adds both to KEV with September 25 federal deadline

What Happened

CVE-2026-85102 — Active exploitation confirmed. TTO-2026-0913-123 documented CVE-2026-85102 as a CVSS 9.8 pre-authentication RCE vulnerability in Check Point Security Gateway’s VPN certificate-handling functionality with exploitation imminent. Exploitation is now confirmed. Starting September 12, attackers began targeting Check Point Spark firewall customers using crafted VPN certificates with subjects including CN=vpn,OU=users,O=global and CN=vpn-user,OU=users,O=global. Attack traffic originated from VPN services and proxies. Check Point has advised organizations to review logs for anomalous certificate-based Mobile Access logins and scan for lateral movement originating from suspicious authenticated sessions.

CVE-2026-93616 — New zero-day disclosed. Check Point has simultaneously disclosed CVE-2026-93616, a path traversal vulnerability in the Management web service of Check Point Management Server. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts on the Management Server, giving them administrative control over firewall policy for the entire environment managed by that server. CVE-2026-93616 was exploited as a zero-day beginning July 23, 2026 — more than 60 days before public disclosure. Check Point states it was aware of “a handful of customers who have been attacked” via CVE-2026-93616. Organizations whose Management Servers were internet-accessible since late July should treat them as potentially compromised and conduct forensic triage alongside patching. This is the fifth Check Point critical vulnerability confirmed exploited in September 2026.

Domain Intelligence

checkpoint.com — 87.0

Score unchanged. checkpoint.com scores at 87.0 in the high-trust range. Check Point is the vendor of the affected products. This is the fifth critical Check Point vulnerability confirmed actively exploited in September 2026.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 23, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026