Hackers Exploit Critical Check Point VPN Flaws to Gain Remote Access Without Login

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Check Point has warned that attackers are actively exploiting two critical vulnerabilities in its VPN and management products, allowing unauthenticated remote access and possible remote code execution.

Both flaws carry a CVSS severity score of 9.8, and the company has released fixes that affected organizations should apply immediately.

The first issue, tracked as CVE-2026-85102, affects Check Point Security Gateway and Spark Firewall deployments that use Remote Access VPN or certificate-based Site-to-Site VPN authentication.

The flaw stems from improper validation of certificate data during VPN negotiation, which can allow a remote attacker to execute arbitrary code without valid credentials.

Check Point released a patch for CVE-2026-85102 on September 9, 2026. At that time, the company had not identified exploitation activity.

Check Point VPN Flaws Exploit

However, Check Point later confirmed that attackers began attempting to exploit the vulnerability against Spark Firewall customers from September 12. The attacks were observed globally and originated from anonymization infrastructure, including VPN services and proxy networks.

Attackers used suspicious VPN certificate subject values such as CN=vpn, OU=users, O=global; CN=vpn-user, OU=users, O=global; and CN=vpnuser, OU=users, O=global. These indicators should not be treated as a complete detection list, as threat actors may use different certificate subjects in future attempts.

The second flaw is a newly disclosed zero-day vulnerability (CVE-2026-93616) affecting Check Point Security Management and Multi-Domain Security Management environments.

It is a pre-authentication directory traversal and file-upload issue that can enable an attacker to upload and execute arbitrary scripts on an exposed management server. Check Point said it knows of a handful of customers targeted in real-world attacks.

CVE-2026-93616 affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products. Smart-1 Cloud, Check Point Firewall Appliances, and Check Point Spark Firewall are not affected by this management-server vulnerability.

The flaw can allow an unauthenticated attacker to abuse directory traversal sequences, such as ../, to access unintended paths and load attacker-controlled content.

In practical terms, successful exploitation could give an intruder a path to execute malicious scripts on a highly privileged management platform, creating risks of firewall policy manipulation, credential theft, network reconnaissance, and lateral movement.

Organizations using vulnerable Check Point products should install the available Jumbo Hotfixes or security hotfixes without delay.

For CVE-2026-85102, Check Point protects LivePatch Take 26 or later supported Jumbo Hotfix releases. The company notes that R82.20 is not affected by this VPN issue.

For CVE-2026-93616, administrators should update to the R82.20 Security Hotfix or supported Jumbo Hotfix versions. Check Point said LivePatch Take 28 and Take 29 do not address this vulnerability, and a LivePatch is not available because of the nature of the required fix.

Administrators should review Mobile Access logs for anomalous certificate-based VPN logins and investigate suspicious activity performed by newly authenticated users.

Internal port scanning or service discovery after a questionable VPN login may indicate second-stage intrusion activity. For management servers, Check Point recommends restricting TCP port 19009 access to trusted IP addresses only.

Security teams should also inspect management logs for unusually long usernames, error messages involving ReflectionUtils, and file paths containing directory traversal patterns. These artifacts may signal an attempted exploit against CVE-2026-93616.

The active exploitation of both flaws highlights the continuing value of patching internet-facing VPN and security-management infrastructure quickly.

These systems often sit at the network perimeter or control critical security policies, making them high-value targets for ransomware operators, access brokers, and state-backed threat actors.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Exploit Critical Check Point VPN Flaws to Gain Remote Access Without Login appeared first on Cyber Security News.