DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

Check Point's September: A VPN Certificate Flaw, a Management Server Gap, and Sixty-One Days

Check Point's September: a VPN certificate flaw, a management server gap, and sixty-one days

Opening

Two Check Point vulnerabilities reached the Known Exploited Vulnerabilities catalogue on 22 September 2026, with a federal remediation deadline of 25 September. One sits in the VPN negotiation path of Security Gateway and Spark Firewall products. The other sits in the web service of the Security Management Server. Read together, they show how a vendor's patch cadence and an attacker's patience interact.

Technical context

CVE-2026-85102 is an improper certificate validation issue, classified CWE-295, affecting Security Gateway and Spark Firewall deployments that terminate site-to-site or remote access VPN. Because a certificate presented during negotiation is not validated correctly, an unauthenticated remote attacker can reach code execution on the gateway. CVE-2026-85103 is an ASN.1 heap overflow in the same product family, scored 9.8, and while it was not confirmed as exploited, it affects the same systems and belongs in the same maintenance window.
The second exploited flaw, CVE-2026-93616, is a path traversal in the Management Server web service that permits unauthenticated file upload and execution. It affects Security Management Server, Multi-Domain Security Management, Log Server, Multi-Domain Log Server and SmartEvent. The consequence of code execution here is qualitatively worse than on a gateway, because the management server holds the firewall policy for every gateway it manages. An attacker who controls it controls the rule set rather than a single host.

Timeline and the take-number trap

Check Point fixed the VPN certificate issue on 9 September 2026 and stated at the time that there was no evidence of exploitation. Attempts against Spark customers began on 12 September, originating from anonymised infrastructure such as commercial VPN and proxy services. Certificate subjects observed in the activity include CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global and CN=vpnuser,OU=users,O=global, and the vendor notes the list is not exhaustive.
For the management server flaw, the vendor reported observing a small number of targeted attacks on 23 July 2026, while the fix shipped with the 22 September advisory. That is a sixty-one day interval between observed exploitation and remediation.
A detail in the advisory causes avoidable errors in the field. A LivePatch released on 16 September, Take 28 or Take 29 depending on release, addressed a different management server vulnerability, CVE-2026-91843, and explicitly does not cover CVE-2026-93616. Teams that recorded a September LivePatch as complete may still be exposed. The affected ranges for the management flaw also extend by one take beyond those for the VPN certificate issue on the R82.10, R82 and R81.20 branches, so checking against the earlier threshold produces a false all-clear.

Defensive implications

Apply the vendor fixes and verify by build number rather than by change ticket. On gateways, fixes for CVE-2026-85102 and CVE-2026-85103 should be treated as one action. Where a gateway cannot be updated, the published workaround is to disable implicit VPN rules and permit UDP ports 500 and 4500 only from known peer addresses; this does not cover locally managed Spark appliances.
Review logs for certificate-based mobile access logins that do not correspond to known users and for port scanning of internal services immediately after any such session, since that is the documented follow-on behaviour. Restrict Management Server web access, commonly on TCP port 19009, to trusted administrative addresses, and preserve web, authentication and system logs before applying changes that could overwrite them.
The strategic lesson is about the gap between a fix existing and a fix being deployed. Attackers picked up the gateway flaw within three days of the patch. Defenders measured their risk from the advisory date rather than the exploitation date. Systems that hold policy for an entire estate deserve the shortest possible pipeline from vendor release to verified installation.

References

Top comments (0)