Check Point CVE-2026-85102 Hit CISA’s KEV — Patch VPN Gateways Before Sept 25

Check Point CVE-2026-85102 Hit CISA’s KEV — Patch VPN Gateways Before Sept 25

September 24, 2026
MicroSky Team
Microsky Blogs

If your Midtown professional firm, Staten Island medical practice, Brooklyn warehouse, or Queens clinic terminates Site-to-Site or Remote Access VPN on a Check Point Quantum Security Gateway or Spark Firewall, treat CVE-2026-85102 as a same-week emergency — not a quiet weekend Jumbo. Check Point Research (Lotem Finkelstein, September 22, 2026) describes a pre-authentication remote code execution flaw in Security Gateway VPN certificate handling. A fix has been available since September 9, 2026. On September 22, 2026, CISA added the CVE to its Known Exploited Vulnerabilities (KEV) catalog with a federal remediation due date of September 25, 2026. Private NYC shops are not under Binding Operational Directive the same way, but a CVSS 9.8 unauthenticated gateway RCE with active exploitation attempts and a three-day federal clock should jump the queue ahead of “nice to have” lifecycle work.

Covered in the same advisory — and the same KEV batch — is companion CVE-2026-93616 (also CVSS 9.8): a pre-authentication path traversal on Check Point Security Management Server / Multi-Domain / Log Server / SmartEvent that can lead to upload and execution of arbitrary scripts. This post is a practical checklist for NYC SMBs and the MSPs who support them. Named sources only: Check Point Research’s September 22 advisory blog, CISA’s KEV catalog entries (dateAdded 2026-09-22, dueDate 2026-09-25), NVD’s CVE summaries, and vendor SKs sk1000117 and sk1000171. No invented percentages. No exploit recipes.

What CVE-2026-85102 actually is (lead with the VPN gateway)

Per Check Point Research and aligned NVD / CISA wording, CVE-2026-85102 is an improper certificate validation issue during VPN negotiation on Security Gateway and Spark Firewall (centrally or locally managed). Improper validation of certificate data during VPN negotiation can allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. That is the highest-relevance path for most NYC SMBs: the box that terminates partner tunnels and remote-worker VPN is also the box adversaries probe first.

Affected product families called out in the vendor advisory table include Security Gateway and Spark Firewall across listed R81 / R81.10 / R81.20 / R82 / R82.10 trains (including end-of-support branches still sitting in closets). Exact builds and takes live in sk1000117 — treat that SK as the authoritative patch map, not a blog paraphrase.

Critical timeline from Check Point Research:

  • September 9, 2026 — vulnerability disclosed and fixes released; at the time, Check Point reported no evidence of exploitation.
  • Starting September 12, 2026 — exploitation attempts observed against Spark customers globally, originating from anonymization infrastructure (VPN services and proxies).
  • Observed certificate subjects in those attempts included CN=vpn, CN=vpn-user, and CN=vpnuser (with OU=users,O=global). Check Point states the list is not exhaustive — other subjects may be in use.

If you already applied the September 9 fix train from sk1000117, Check Point’s advisory says you are already protected for this CVE. If you have not, you are behind both the vendor fix window and CISA’s KEV due date.

Companion CVE-2026-93616 — management-plane zero-day

Separately, Check Point Research identified a handful of pinpointed attacks on July 23, 2026 against CVE-2026-93616: a pre-authentication path traversal in the Check Point Management web service that allows an attacker to execute a script from an arbitrary path and load an arbitrary Java class. CISA’s KEV entry describes Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent as affected products, with the same 2026-09-22 add date and 2026-09-25 due date.

Operator-critical notes from the vendor advisory and sk1000171:

  • Affected version/take ranges include R82.20 and listed Jumbo Hotfix ceilings on R82.10 / R82 / R81.20 / R81.10, plus older R80/R81 end-of-support trains.
  • Check Point LivePatch Take 28/29 does NOT address this issue. Do not assume a LivePatch you already applied for another problem covers 93616.
  • Smart-1 Cloud is called out as already fixed; firewall appliances and Spark Firewall are not the management-plane target for this CVE.
  • A fix is available now as part of the September 22 advisory — Jumbo / hotfixes per sk1000171.

Gateway RCE (85102) and management script execution (93616) are different blast radiuses. Patch both. Do not invent a “one Jumbo fixes everything” story unless sk1000117 and sk1000171 both confirm your exact take.

Why CISA put both on the KEV — and why September 25 matters

CISA’s Known Exploited Vulnerabilities catalog lists both CVEs with:

  • Date added: 2026-09-22
  • Due date: 2026-09-25
  • CVE-2026-85102 — Check Point Multiple Products Improper Certificate Validation Vulnerability (CWE-295)
  • CVE-2026-93616 — Check Point Multiple Products Path Traversal Vulnerability (CWE-22)
  • Known ransomware campaign use: Unknown (per KEV entries cited here)

Required action language points agencies at vendor instructions (sk1000117 / sk1000171), BOD 26-04 risk-based update guidance, and forensics triage expectations for exposed assets. For a five-person accounting firm on South Avenue or a multi-site practice in Queens, the practical takeaway is simple: when Check Point says exploitation attempts are in the wild against Spark VPN customers and CISA puts a three-day federal clock on the same CVEs, you do not wait for the next “quiet” maintenance window if any Quantum/Spark gateway or on-prem management server is still on an affected build.

What to do this morning (MSP / NYC SMB checklist)

1. Inventory every Check Point Quantum / Spark gateway and every management server

List model/appliance, serial, management IP, software train (R81.x / R82.x), Jumbo Hotfix take, VPN role (Site-to-Site, Remote Access / Mobile Access), and whether the gateway or management web UI is reachable from the internet, partner networks, or flat user VLANs. Include “temporary” Spark boxes that became permanent at a Brooklyn warehouse, secondary sites in Queens, and SmartEvent / Log Server hosts people forgot were still on-prem. Confirm you are not confusing gateway appliances with management servers — different CVEs, different SKs.

2. Patch CVE-2026-85102 per sk1000117

Schedule an emergency change for every affected Security Gateway and Spark Firewall. Land on the fixed builds/takes documented in sk1000117. Plan a brief outage window: VPN tunnels drop, remote workers bounce, partner Site-to-Site may need rekey. For Midtown firms that still live on Remote Access for hybrid staff, document rollback images and a re-enrollment path before you start. Customers who applied the September 9 fix are already covered for this CVE per Check Point Research — verify that claim against your actual take, do not assume.

3. Patch CVE-2026-93616 per sk1000171 — and do not trust LivePatch 28/29

Apply the Security Management / Multi-Domain / Log Server / SmartEvent fixes from sk1000171 (including the Jumbo takes Check Point lists as including the fix). Explicitly: LivePatch Take 28/29 does not fix 93616. If your only “we patched management” evidence is a LivePatch take in that range, you still have work. Shrink management web exposure while you stage the Jumbo — jump hosts, VPN-only admin, no open internet to the management GUI — but exposure reduction is not a substitute for the SK fix.

4. Hunt Mobile Access / anomalous certificate logins

Check Point Research recommends reviewing logs for anomalous certificate-based Mobile Access logins — and not limiting the search to the sample subjects (CN=vpn / CN=vpn-user / CN=vpnuser). Look for second-stage activity from suspicious logged-in users via Mobile Access; follow-up often involves internal port and service scans. Preserve logs before you wipe anything that looks off. Use Check Point’s published hunting guidance in the advisory and sk1000171 for management-side IoCs — do not invent indicators.

5. Review management web exposure

For every Security Management Server, Multi-Domain, Log Server, and SmartEvent instance: is the management web service reachable from untrusted networks? If yes, treat that as elevated urgency for 93616 even before the Jumbo lands. Smart-1 Cloud customers should confirm they are on the already-fixed cloud path per vendor notes; on-prem management stays your problem until sk1000171 is applied.

6. If compromise is suspected — rebuild trust, do not “clean in place”

Treat a gateway that may have executed unauthenticated remote code, or a management server that may have run attacker scripts, as untrusted infrastructure. Follow Check Point’s forensics / IoC guidance in the SKs, preserve evidence, rotate VPN and admin credentials, review Mobile Access user sessions, and re-validate policy after rebuild. A firewall that “mostly forwards packets” after a root-capable incident is not a success criterion. Align with CISA’s BOD 26-04 forensics triage expectations if you are in scope or simply want the same discipline.

How MicroSky thinks about this for managed clients

VPN gateways and management servers are easy to defer until they are the beachhead. Staten Island offices, Queens clinics, and Manhattan professional firms often treat Check Point Quantum/Spark gear as “set and forget” edge — until a certificate-validation RCE on VPN negotiation or a management path traversal turns that edge into arbitrary code execution. We treat KEV-listed firewall and management the same way we treat recent switch, identity, and email-gateway KEVs covered elsewhere on this blog (for example our notes on Zyxel GS1900 CVE-2026-7273 and Cisco ISE CVE-2026-76460): inventory first, emergency patch second, log hunting and exposure shrink third, rebuild and credential rotation if anything looks off.

Pack for this post: in-house SA-research (not native Content Genius). Facts are limited to the named Check Point, CISA, NVD, and SK sources above.

Need a hand before September 25?

If you need a same-day inventory of Check Point Quantum/Spark gateways and management servers, help applying sk1000117 / sk1000171, or a Mobile Access / anomalous-cert log review before CISA’s September 25 due date, call MicroSky Managed Services at 718-672-2177 or visit https://microskyms.com. We are a Staten Island–based MSP serving NYC SMBs who would rather patch the VPN edge on purpose than discover it in an incident ticket.

Want help applying this to your business?

MicroSky provides managed IT, cybersecurity, and web services for NYC businesses. If you want a clear plan and a responsive team, let's talk.

Newsletter

Stay on Top of Tech. Subscribe Today.

    Check Point CVE-2026-85102 Hit CISA’s KEV — Patch VPN Gateways Before Sept 25 | MicroSky Blog | MicroSky Managed Services, Inc.