1. Basic Information
- Original Title: Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616
- Published Date: 2026-09-22
- Updated Date: None
- Collection Date: 2026-09-24T08:09:37+09:00
- Source: Check Point
- Severity: critical
- Type: Threat Intelligence
- Target Period: 2026-09-23T08:14:06+09:00 - 2026-09-24T08:09:37+09:00 (Asia/Tokyo)
- Original Link: Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616
- Related Sources: BleepingComputer: Check Point warns of hackers exploiting Security Gateway VPN RCE flaw, BleepingComputer: Dutch NCSC warns exploitation is imminent, Netherlands NCSC alert, Check Point Security Gateway advisory
- Basis for Severity: This is a VPN certificate processing vulnerability leading to pre-authentication RCE, and Check Point has confirmed active exploitation attempts globally. While the official advisory highlights suspicious logins and internal reconnaissance as key areas for investigation, the exact number of compromised environments and the scope of subsequent damage have not been publicly disclosed.
- Reason for Update: Re-verified today's update reflecting active exploitation information from the September 22 official advisory, and separated the VPN certificate processing from subsequent investigations via Mobile Access. Revised patch levels by product, success criteria, and English phrasing.
2. Executive Summary
Check Point has confirmed active exploitation attempts targeting Spark users since September 12 regarding CVE-2026-85102, a vulnerability in VPN certificate processing. Organizations are urged to investigate abnormal certificate-based Mobile Access logins and subsequent internal reconnaissance.
3. Attack Flow
Exploitation Attempts Targeting VPN Certificate Processing and Recommended Follow-up Investigations
- An attacker reaches the vulnerable VPN processing on an unpatched Security Gateway or Spark Firewall. The vulnerability lies in certificate data validation during VPN negotiation and is not limited to the Mobile Access portal alone.
- Since September 12, 2026, Check Point has observed exploitation attempts using anonymous VPNs or proxies, along with certificates containing specific subjects.
- The official advisory recommends investigating unusual certificate-based Mobile Access logins and subsequent internal port and service discovery by suspicious login users. The complete procedure from initial exploitation to these actions, as well as individual success counts, has not been publicly disclosed.
4. Attacker Position and Execution Location
- Unauthenticated external attackers able to reach the vulnerable VPN certificate processing
- Attackers using anonymous VPNs or proxies
- Inference: Entities attempting to access internal services via VPN sessions or similar means after a compromise
5. Visibility for Victims and Administrators
Victims
- May appear as VPN re-authentication requests or connection errors
Administrators and SOCs
- Suspicious certificate-based Mobile Access logins
- Certificate subjects where the CN is vpn, vpn-user, or vpnuser
- Unusual source ASNs/IPs and devices
- Internal port and service discovery following logins
- Unknown processes, files, or configuration changes on the gateway
6. Success and Failure Conditions
Success Conditions
- The necessary updates have not been applied to the affected Security Gateway or Spark Firewall.
- Crafted certificate data reaches the vulnerable VPN processing.
- Available sessions, privileges, and communication paths exist for subsequent internal access.
Failure Conditions and Mitigations
- According to the official steps cited by BleepingComputer, patch levels by product are R81.20 Take 166, R82 Take 126, R82.10 Take 44, and R81.10 Take 190 or later for Security Gateways. Apply the correct patches for your product and family.
- For Spark Firewalls, update to fixed firmware version R82.00.10 Build 2325 or later, or R81.10.17 Build 4968 or later. Note that LivePatch is not recommended for Spark.
- LivePatch Take 26 is intended for supported R81.20, R82, and R82.10 gateways. Distinguish this from permanent fixes, and verify applicable configurations and protection status using Check Point's documentation.
- Restrict inbound access to the VPN service to the absolute minimum necessary. Official alternative workarounds, such as modifying implicit Site-to-Site VPN rules, cannot be applied to locally managed Spark appliances.
- Investigate suspicious certificates, accounts, and sessions, and restrict internal access privileges. Address existing compromises separately from applying vulnerability patches.
7. Impact Upon Success
- Remote code execution on the gateway
- Unauthorized Mobile Access logins and sessions
- Internal port and service discovery
- Potential escalation to credential theft, lateral movement, and additional system compromises
8. Observable Logs
- No email vectors have been reported
Proxy / SWG / DNS
- Connections to the Mobile Access portal originating from anonymous VPNs or proxies
- Communication from the gateway to unknown external hosts
Endpoint / EDR
- Unknown processes, files, configuration changes, or shell commands on the gateway
Identity / IdP
- Certificate-based Mobile Access logins
- Certificate subjects: CN=vpn,OU=users,O=global; CN=vpn-user,OU=users,O=global; CN=vpnuser,OU=users,O=global
- Sources, devices, or timeframes differing from normal baselines
SaaS / Cloud
- SmartConsole or management audit records, policy/hotfix/firmware states, and VPN user/session logs
Network
- Internal port and service discovery immediately following suspicious logins
- Short-duration connections from the gateway or VPN address pool to numerous hosts and ports
9. Attack Success Determination
Confirmed in Public Information
- Attack attempts observed (success unconfirmed): Public info: Check Point has disclosed active exploitation and indicated requests and certificate subjects targeting Spark users since September 12. Specific code execution results and the number of compromised organizations have not been made public. Scope: Exploitation attempts specifically detailed in the official advisory.
Internal Organization Criteria
- Malware execution or successful authentication confirmed: Criteria: Verify successful logins using suspicious certificates and unauthorized use of those sessions within your organization. Recommendations for investigation alone do not constitute confirmed individual success. Scope: Determination of successful authentication within the organization.
- Subsequent compromise confirmed: Criteria: Back up unauthorized authentication, code execution, or data theft following internal reconnaissance with evidence from destination hosts. Port discovery alone does not confirm a successful internal host compromise. Scope: Determination of subsequent compromise within the organization.
10. Investigation Playbook
Triggers
- Unpatched gateways, abnormal certificate logins, known subjects, anonymous sources, and post-login internal reconnaissance
Initial Triage
- Verify product model, version, patch level, and the exposure scope of the VPN service. For Spark, check the firmware status; for supported gateways, check the Jumbo Hotfix or LivePatch application status.
- Preserve gateway, Mobile Access, management, and flow logs in UTC.
- Compare certificate logins since September 12 against normal baselines.
Endpoints and Servers
- Investigate gateway processes, files, cron jobs, services, configurations, and support diagnostic data.
- Check command execution and outbound connections around the time of exploitation.
Authentication and Cloud
- Revoke suspicious certificates, users, and sessions; rotate and revoke related credentials and certificates.
- Track logins to other services using the same accounts.
Follow-up Actions
- Check for port discovery and internal authentication originating from the VPN address pool and gateway.
- Investigate destination hosts using EDR for new processes, accounts, or access to credentials.
Containment
- Apply the product-specific patches outlined in Section 6, and restrict exposure of vulnerable VPN services as needed.
- Isolate or rebuild the gateway, and rotate/revoke sessions, credentials, and certificates.
- Implement internal network segmentation and block outbound communication.
Decision Categories
- Record exploitation requests, unauthorized logins, internal reconnaissance, and successful internal host compromises separately.
11. Defense and Detection Ideas
Single Events
- Certificate-based Mobile Access logins outside of normal baselines
- Logins from known subjects or anonymous sources
- Internal reconnaissance originating from the gateway
Timeline Correlation
- Correlate external exploitation indicators -> certificate logins -> connections to numerous internal ports within a short timeframe.
Threat Hunting
- Re-evaluate all certificate logins since September 12 based on sources, ASNs, devices, and times rather than subjects alone.
- Search for internal reconnaissance via east-west traffic originating from the VPN address pool and gateway IPs.
Log Gaps
- Because local gateway logs alone cannot determine the success or failure of internal reconnaissance destinations, firewall, NetFlow, and EDR data are required.
Priority Countermeasures
- Emergency patching
- Reducing Mobile Access exposure
- Detecting anomalies in certificate logins
- Network segmentation
- Detecting internal reconnaissance originating from gateways
12. Facts, Inferences, and Hypotheses
Facts
- Check Point released fixes for CVE-2026-85102 starting September 9, 2026, and confirmed global exploitation attempts targeting Spark appliances beginning September 12.
- Attacks were conducted from anonymous VPNs and proxy infrastructures, observing certificate subjects: CN=vpn,OU=users,O=global; CN=vpn-user,OU=users,O=global; CN=vpnuser,OU=users,O=global.
- Check Point urges investigating all unusual certificate-based Mobile Access logins, not just those matching known subjects.
- The official advisory recommends investigating subsequent activity from suspicious Mobile Access login users, noting that internal port and service discovery are frequently involved. It does not state specific numbers of successful authentications or compromises.
- CVE-2026-85102 is a pre-authentication RCE in Security Gateway VPN certificate processing. Observed exploitation attempts target Spark users. CVE-2026-85103 is a separate vulnerability, and the official advisory does not report active exploitation for it.
- Product-specific patch levels and LivePatch instructions are as described in Section 6. A distinction must be made between fixed firmware for Spark and LivePatches for supported gateways.
Inferences
- Because certificate subjects can be easily modified, evaluations must combine source metadata, devices, login sequencing, and subsequent reconnaissance rather than relying solely on fixed strings.
- Internal reconnaissance following a VPN gateway compromise will be overlooked if pre-authentication exploitation is treated merely as a remote access account compromise.
Hypotheses
No additional hypotheses. Unconfirmed items are noted under "Unknowns and Additional Investigation."
13. MITRE ATT&CK Mapping
| ID | Technique | Confidence | Basis |
|---|---|---|---|
| T1190 | Exploit Public-Facing Application | high | Exploitation attempts targeting pre-authentication RCE in VPN certificate processing. |
| T1078 | Valid Accounts | medium | Suspicious certificate-based logins highlighted in the official advisory for investigation. Individual success counts unpublicized. |
| T1046 | Network Service Discovery | high | Post-login internal port and service discovery described in the official advisory, distinct from successful compromise of destination targets. |
| T1090 | Proxy | high | Connections originating from anonymous VPN and proxy infrastructures. |
14. Unknowns and Additional Investigation
- Number of gateways where code execution was successfully achieved
- Attacker attribution and payloads
- Number of host compromises successfully achieved following internal reconnaissance
- Active exploitation status of CVE-2026-85103
- Certificate patterns other than observed subjects
15. Impact on SOCs and Organizations
Organizations utilizing Spark and Mobile Access products should retrospectively investigate certificate logins since September 12, ensuring they do not filter out events based solely on subject matching. Treat internal reconnaissance originating from gateways as a high-priority incident, and simultaneously verify patches, sessions, certificates, and internal hosts.
16. Summary by Role
SOC
Track certificate logins, anonymous sources, and reconnaissance originating from gateways and VPN address pools as a single attack chain.
Administrators
Apply fixed firmware for Spark and corresponding patches for gateways, and investigate VPN exposure scopes and certificate-based sessions.
General Users
If you receive suspicious VPN re-authentication or connection notifications, do not accept certificates on your own judgment and contact the management department.
Top comments (0)