Skip to content

Security1 publisher2 min readPublished

Check Point patches a Security Management zero-day it saw exploited on July 23

The advisory confirming attacks on a Security Gateway VPN flaw three days after its September 9 fix also carries the first patch for a management path traversal that was used in targeted attacks in late July.

The Watch · Security desk

Illustration accompanying Check Point patches a Security Management zero-day it saw exploited on July 23

What happened

  • Check Point Research says it is seeing exploitation attempts worldwide against Spark customers aimed at CVE-2026-85102, a pre-authentication remote code execution bug in Security Gateway VPN certificate handling.
  • Check Point says a handful of pinpointed attacks using the management flaw took place on July 23, 2026, when it was still an undisclosed zero-day.
  • The gateway attempts came through VPN services and proxies and used client certificates with subjects including CN=vpn,OU=users,O=global, a list Check Point says is not exhaustive.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Anyone who closed a Check Point patching ticket in September has a second one to open, on a different box: the gateway hotfix leaves the management web service unfixed.
  • exposure Spark operators who deferred the September 9 fix to a maintenance window are now being probed from proxy and VPN infrastructure.
  • precedent With the management flaw used before it was known, log retention decides whether a compromise from late July is findable at all.

Neither bug needs credentials. CVE-2026-85102 gets code execution on a Security Gateway through VPN certificate handling [1]. CVE-2026-93616 lets an attacker execute a script from an arbitrary path and load an arbitrary Java class through the Check Point Management web service [6].

They sit on different boxes, so they need different tickets. A gateway that took the September 9 hotfix is protected against 85102, according to Check Point [4]. That hotfix does not touch the management server, which needs the fix released with this advisory [6].

The advisory's own heading calls 85102 "One day exploitation, patch available since September 9" [3]. The wave it then describes against Spark customers starts September 12, three days after the fix shipped [5][11]. Attempts arrived through VPN services and proxies and used client certificates with the subjects CN=vpn, CN=vpn-user and CN=vpnuser, all under OU=users and O=global [9]. Check Point says those are only the subjects observed so far and that other subjects may be in use [10].

The management flaw is the older incident. Check Point dates the pinpointed attacks to July 23, 2026, and the fix arrives with this advisory, published on or after the September 12 gateway wave it reports [8][5]. Counting July 23 to September 12 gives at least 51 days in which the flaw was in use with no fix available [12]. A hunt on the management server therefore begins in late July, and the indicators are in sk1000171 [13].

For the gateway, the guidance is log work: review anomalous certificate-based Mobile Access logins, and do not limit the search to the three published subjects [14]. Then look at what those accounts did next. Follow-up activity often involves internal port and service scanning, according to Check Point [15].

The advisory body does not list affected takes and builds; Check Point puts those, with validation commands and alternative mitigation steps, in the per-product advisories it links [16]. Both fixes ship as Jumbo hotfixes, which Check Point releases under what it calls its Frontier AI Readiness Program [17]. Spark is the customer set it names for the observed 85102 attempts, and it describes that activity as global [2].

What to watch

  • Whether Check Point reports CVE-2026-85102 exploitation against gateway lines other than Spark.
  • Whether the certificate subject list or the sk1000171 indicators are expanded, or an actor is named for the July 23 attacks.
  • Whether the handful of pinpointed CVE-2026-93616 cases grows once customers start hunting back to late July.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories