Serial Number: AV26-902
Date: September 9, 2026
Updated: September 22, 2026
As of September 9, 2026, Check Point is affected by vulnerabilities in the following products:
- Security Gateway
- Multiple versions
- Check Point Spark Firewall using Site to Site VPN or Remote Access VPN
- Multiple versions
- Security Management Server
- Multiple versions
- Check Point Spark Firewall
- Multiple versions
Update 1
Check Point has reported that CVE-2026-85102 and CVE-2026-93616 are being exploited in the wild.
Update 2
On September 22, 2026, Cybersecurity and Infrastructure Security Agency (CISA) CVE-2026-85102 and CVE-2026-93616 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- CVE-2026-85102 - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN
- CVE-2026-85103 - ASN.1 decoding heap overflow leading to a remote code execution
- Check Point Security
- Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616
- CISA KEV: CVE-2026-85102
- CISA KEV: CVE-2026-93616


