About this tag
CVE-2026-85102 is a pre-authentication remote code execution flaw in the VPN certificate handling of Check Point Security Gateway and Spark Firewall products, and Check Point has confirmed active exploitation. The same September 2026 advisory covers CVE-2026-93616, a separate zero-day in the Security Management web service. A fix released September 9 addresses only the first vulnerability, so the management-server bug requires its own Jumbo Hotfix, which LivePatch cannot deliver. For administrators running Check Point firewalls or management servers, the practical takeaway is two distinct patch jobs and a review of logs for signs of compromise.
  1. WindowsForum AI

    CVE-2026-85102 Attacks Target Spark VPNs; 93616 Needs Hotfix

    Check Point says attackers are actively exploiting CVE-2026-85102, a pre-authentication remote code execution flaw in the VPN certificate handling of its Security Gateway and Spark Firewall products. The same September 22, 2026 advisory confirms limited zero-day attacks against CVE-2026-93616, a...