Check Point CVE-2026-93616 exploitation

Flag of the U.S. Cybersecurity and Infrastructure Security Agency
U.S. Cybersecurity and Infrastructure Security Agency; public domain. Vectorization by Leonard LMT.

Check Point CVE-2026-93616 exploitation is the central phrase for this report because it captures the specific development readers need to evaluate. Federal agencies received a three-day deadline to patch and investigate two 9.8-rated gateway and management-server bugs; remediation alone is not enough.

Two flaws, one unusually short clock

CISA added CVE-2026-85102 and CVE-2026-93616 to its Known Exploited Vulnerabilities catalog September 22 and set a September 25 federal deadline. Both carry CVSS scores of 9.8. Under BOD 26-04, agencies must conduct forensic triage as well as apply fixes—a signal that CISA is concerned some environments may already be compromised.

What each vulnerability exposes

CVE-2026-85102 involves improper certificate validation during IKEv2 VPN negotiation and can enable unauthenticated code execution on affected Security Gateway and Spark appliances using site-to-site or remote-access VPN. CVE-2026-93616 is a pre-authentication path-traversal and file-upload flaw in the Security Management Server web service, which can allow arbitrary scripts to run in the system that controls policies, logs and gateways.

The exploitation timeline

Check Point reported exploitation attempts against Spark customers beginning September 12 and a handful of targeted zero-day attempts involving the management flaw as early as July 23. Fixes shipped September 9 in advisories sk1000117 and sk1000118; R82.20 was reported unaffected. The Dutch NCSC had warned that exploitation of the gateway issue was likely.

Why patching alone is inadequate

If an attacker reached a management server before it was fixed, installing the update does not remove persistence, restore trustworthy logs or rotate exposed credentials. Security teams need to identify suspicious uploads and processes, preserve evidence, check managed gateways and review administrative changes. A clean version number answers whether the door is closed now, not whether somebody entered earlier.

Who is exposed and what comes next

Federal agencies are directly bound by the deadline, but enterprises and managed-security providers face the same technical risk. Internet-facing management planes and VPN gateways deserve priority. Incident-response vendors benefit from emergency demand; affected operators bear outage and investigation costs. The next public test is whether exploitation remains targeted or expands into mass ransomware activity—and whether post-incident reviews reveal compromises that patch-only programs missed.

Related Signal Post News coverage

the separate TeamCity ransomware warning the limits and promise of security automation

Sources and reporting basis

Reporting note: This is a fixed September 25, 2026 snapshot. Attributed claims remain attributed; forecasts, polls, vendor results and early cyber findings can change as new evidence appears.

Technology / Cybersecurity · Published September 25, 2026Back to latest reports