Check Point has issued an urgent security advisory covering two critical vulnerabilities that are now being exploited in real-world attacks, and the combination should be treated as more than another emergency patching event. One vulnerability affects the Security Gateway itself, while the second affects the centralized Security Management layer that governs the environment. Together, they illustrate a problem that deserves much more attention at CISO level: the infrastructure responsible for protecting the enterprise can itself become one of the most valuable attack surfaces.
The first vulnerability, CVE-2026-85102, is a pre-authentication remote-code-execution flaw in the VPN certificate-handling functionality of Check Point Security Gateway. Check Point disclosed the vulnerability and released fixes on 9 September, initially stating that it had no evidence of exploitation. That situation has since changed significantly, with Check Point reporting a wave of exploitation attempts against Spark customers beginning on 12 September and affecting organizations globally.
The second vulnerability, CVE-2026-93616, is arguably even more important from an architectural perspective because it targets the management plane rather than the gateway itself. Check Point describes it as a pre-authentication path-traversal vulnerability in the Management web service that can allow an attacker to execute a script from an arbitrary path and load an arbitrary Java class. The vendor assigns the vulnerability a CVSS score of 9.8 and says it observed a limited number of targeted attacks exploiting the flaw as early as 23 July 2026, almost two months before the public disclosure and availability of the fix.
What makes this combination particularly serious is not simply that both vulnerabilities can be exploited before authentication, but that they affect two different layers of the same security architecture: the enforcement point and the system responsible for managing that enforcement. Check Point confirms that both flaws carry a CVSS score of 9.8 and are associated with products central to network-security operations.
Why this matters beyond Check Point
Security infrastructure is often granted a level of implicit trust that ordinary application systems do not receive. Firewalls, VPN gateways, security-management consoles, SIEM platforms, endpoint-security controllers and privileged-access systems are deployed specifically to enforce security policy, and they therefore tend to sit in highly trusted parts of the environment with broad administrative authority and visibility.
That trust becomes a liability when one of these systems is compromised.
CVE-2026-85102 demonstrates the risk at the gateway layer, where an unauthenticated attacker may exploit certificate-handling weaknesses during VPN negotiation and obtain remote code execution. CVE-2026-93616 moves the problem deeper into the control plane, where the affected system is responsible for central management, policy administration and security operations.
From a CISO perspective, the management-plane vulnerability deserves special treatment because compromise of a centralized security-management platform cannot be assessed in the same way as compromise of an isolated application server. A system that controls policy distribution, administrative changes and security visibility should be considered a Tier-0 or crown-jewel asset, because its compromise may undermine confidence in the controls it manages rather than merely affecting the host itself.
This distinction is increasingly important across the industry. Asset criticality should not be based only on the business function provided by a system; it should also account for the security authority that system holds over the rest of the organization.
The management plane is now part of the attack surface
CVE-2026-93616 affects Check Point Security Management environments, including current and older supported and end-of-support releases. Check Point lists vulnerable builds across R82.20, R82.10, R82, R81.20 and R81.10, as well as older versions that have already reached end of support.
An especially important operational detail is that LivePatch Take 28/29 does not address this vulnerability. Organizations therefore cannot rely on a generic “fully patched” status in their dashboards; the relevant dedicated hotfix or corrected Jumbo Hotfix level must be explicitly verified.
This is exactly the kind of situation in which vulnerability-management metrics can become misleading. A management server may appear up to date from an operational perspective while still remaining exposed to a critical pre-authentication vulnerability. For high-authority security systems, CISOs should therefore insist on validation of the exact build and hotfix level rather than accepting a broad statement that patching has been completed.
Patching alone does not close the incident
Because exploitation is already confirmed, remediation should not stop once the software is updated.
Check Point says exploitation attempts against CVE-2026-85102 have been observed since 12 September and advises customers to review logs for anomalous certificate-based Mobile Access activity as well as follow-on behavior from suspicious authenticated users, including internal port and service scanning.
For CVE-2026-93616, Check Point directs customers to dedicated guidance containing mitigation steps, hunting procedures and indicators of compromise, which reinforces the fact that the correct response is not simply to install a fix and close the vulnerability ticket.
Once a vulnerability has been exploited before remediation, the workflow must change from ordinary vulnerability management to compromise assessment. The relevant sequence becomes:
identify the affected system, reduce exposure, patch, hunt, validate, and only then restore trust.
A patched system that was previously compromised is still a compromised system unless the organization can establish otherwise.
That is especially true for management infrastructure, where an attacker may have obtained access before the public advisory was issued.
Historical exposure matters
Check Point says it observed targeted exploitation of CVE-2026-93616 on 23 July, while the public disclosure and fix came on 22 September.
That creates a potentially significant historical exposure window.
For organizations whose management interfaces were reachable by untrusted networks during that period, the relevant question is not simply whether the hotfix has now been applied, but whether an attacker may already have interacted with the system before the fix existed.
This distinction is fundamental.
Patch status describes the system today.
Incident response must determine what happened yesterday.
For security-management infrastructure, that investigation should include a review of administrative activity, policy changes, unexpected processes, suspicious files, unusual outbound communication and independent security telemetry that exists outside the affected platform.
The last point is particularly important because a compromise of a security-management or logging system can weaken confidence in the logs stored locally on that same system. Critical telemetry should therefore always have an independent destination.
Who is affected
CVE-2026-85102 affects Security Gateway and Spark Firewall deployments across multiple releases, including older R81 and current R82 branches. Check Point’s advisory confirms that the flaw is actively exploited and that customers who have not yet installed the available fix should do so immediately.
CVE-2026-93616 affects Security Management infrastructure across current and older versions, including systems running vulnerable Jumbo Hotfix Takes. The fact that older end-of-support releases remain in scope should be particularly concerning for organizations that have postponed upgrade programs and continue to rely on compensating controls.
For these environments, the incident should serve as an additional argument for reducing technical debt in security infrastructure itself. Security platforms that remain on unsupported or aging releases can become disproportionately valuable targets precisely because they combine high privilege with slower remediation cycles.
The broader business risk
The confirmed technical impact is already serious enough: unauthenticated remote code execution on a security gateway and arbitrary script execution on security-management infrastructure.
What Check Point has not publicly disclosed is what the attackers did after gaining access during the observed incidents. It would therefore be inappropriate to claim that policy manipulation, credential theft, lateral movement or log tampering definitely occurred.
However, these are exactly the categories that incident responders should investigate once unauthorized code execution has occurred on a security control plane.
The business risk is not limited to outage or system availability. A compromised management platform can create uncertainty around policy integrity, administrative activity, visibility, credential exposure and downstream systems that depend on the compromised control plane.
For executive management, that uncertainty is itself a material risk.
CISO Node risk assessment: Critical
The current situation deserves a Critical rating for affected and exposed installations because the two vulnerabilities combine several of the highest-risk characteristics an enterprise security team can face: pre-authentication exploitation, remote code execution, CVSS 9.8 severity, confirmed in-the-wild activity and compromise of infrastructure specifically designed to protect or manage other security systems.
Check Point’s recommendation is unambiguous: fixes are available and affected customers should install them immediately.
The more mature CISO response, however, should go further.
Every organization should verify the actual software and hotfix level of its Check Point gateway and management infrastructure, determine whether affected systems were reachable during the known exposure window, apply the dedicated fixes, investigate published indicators and suspicious activity, and review whether security-management platforms are sufficiently segmented from untrusted networks.
For CVE-2026-85102, Check Point specifically recommends reviewing anomalous certificate-based Mobile Access logins and subsequent activity from suspicious sessions.
For the management vulnerability, the organization should assume that patching without historical compromise assessment leaves an unanswered risk.
Board and executive perspective
There is a simple way to translate this incident for a board.
The systems that protect the company are themselves privileged systems and must therefore be protected at least as aggressively as the business applications they defend.
A useful board discussion should focus on three questions.
First, which security-management platforms have administrative authority across large parts of the enterprise?
Second, how quickly can known-exploited vulnerabilities in those platforms be remediated?
Third, if one of those systems is compromised, does the organization possess independent telemetry and recovery capability sufficient to determine what happened and restore trust?
Those questions provide a far more meaningful view of resilience than a generic patch-compliance percentage.
