zero-day • BleepingComputer

Check Point bekrefter aktiv utnyttelse av RCE-sårbarheter i Security Gateway VPN og Management Server

Check Point advarer om aktiv utnyttelse av to kritiske sårbarheter — CVE-2026-85102 i VPN-sertifikathåndtering og CVE-2026-93616 i Management Server — med angrep mot Spark-kunder siden 12. september. CISA krever patching innen 25. september.

Check Point bekrefter aktiv utnyttelse av RCE-sårbarheter i Security Gateway VPN og Management Server

Check Point confirmed on September 24, 2026, that unknown attackers are actively exploiting two severe flaws in its Security Gateway platform and Management Server. The first, CVE-2026-85102, enables unauthenticated RCE through faulty VPN certificate handling on Security Gateway and Spark appliances. The second, CVE-2026-93616, is a pre-authentication path traversal in the Management Server web service exploited as a zero-day since July 23. Attacks against Spark customers surged from September 12 via VPN tunnels and proxy infrastructure — days after the Dutch NCSC warned that Gateway exploitation was imminent.

The vulnerabilities strike organizations that depend on Check Point perimeter firewalls and centralized policy management. CVE-2026-85102 sits in how Security Gateway parses certificate subjects during VPN authentication: an attacker can submit crafted certificates and trigger arbitrary code execution before any user logs in. In the wild, defenders have observed subject fields such as `CN=vpn,OU=users,O=global`, `CN=vpn-user...`, and `CN=vpnuser...` — patterns that diverge from legitimate client certificates and should trigger immediate log review.

The Management Server flaw is equally dangerous for internal networks. Path traversal lets attackers read or write files outside intended directories by manipulating paths in HTTP requests. Check Point confirms in-the-wild exploitation since summer, implying at least one actor knew of the bug before public disclosure. Together — perimeter RCE plus centralized management compromise — the pair gives intruders both an external foothold and lateral leverage.

The timeline explains the urgency. On September 10, the Netherlands NCSC issued a pre-alert that the Gateway issue would likely see broad exploitation soon. On September 12, a wave of attacks hit Spark environments, often through VPN access and compromised proxy paths. CISA added both CVEs to its Known Exploited Vulnerabilities catalog with a mandatory federal patch deadline of September 25, 2026 — a signal every Nordic Check Point customer should treat as binding guidance.

Check Point offers multiple remediation tracks by version. LivePatch Take 26 addresses the issue without full reboot in some deployments. Jumbo Hotfix builds cover R81.20 Take 166, R82 Take 126, R82.10 Take 44, and R81.10 Take 190. Spark customers should upgrade to R82.00.10 Build 2325 or R81.10.17 Build 4968. Where patching cannot happen immediately, the vendor advises disabling VPN implied rules and restricting UDP 500 and 4500 (IKE/IPsec) to known peer addresses — a disruptive emergency measure that blocks the simplest attack path.

For DFIR teams, priority log sources include VPN authentication, certificate issuance, and Management Server access from July onward. Compare certificate common names against internal templates, hunt for unusual proxy chains, and correlate with the CISA KEV timeline.

Evidence Rail

  • Confirmed: Check Point security advisory; CISA KEV listing; Dutch NCSC pre-alert September 10; active Spark exploitation from September 12.
  • Reported: Certificate patterns CN=vpn, vpn-user, vpnuser* observed in wild attacks.
  • Unconfirmed: Specific threat group attribution or state-sponsored APT linkage.

Concrete steps for IT and security leaders

1. Inventory every Security Gateway, Spark, and Management Server instance and map versions against Check Point's patch matrix today. 2. Apply LivePatch Take 26 or the relevant Jumbo Hotfix; schedule maintenance for Spark builds where uptime allows. 3. Interim: disable VPN implied rules and restrict UDP 500/4500 to known peers if patching is delayed. 4. Review VPN and Management logs from July 23 and September 12 respectively; flag anomalous certificate subjects. 5. Escalate suspected compromise to internal incident response and relevant regulators.

In Brief

  • Two pre-auth flaws — VPN certificate RCE and Management path traversal — are actively exploited since July and September respectively.
  • Spark customers faced an exploitation wave from September 12; CISA patch deadline is September 25.
  • Mitigation requires rapid patching or, failing that, blocking VPN implied rules and IKE ports until systems are updated.

Kilder og referanser

← Alle nyheter Verktøy