Check Point CVE-2026-93616 exploitation

Check Point CVE-2026-93616 exploitation is the central phrase for this report because it captures the specific development readers need to evaluate. Federal agencies received a three-day deadline to patch and investigate two 9.8-rated gateway and management-server bugs; remediation alone is not enough.
Two flaws, one unusually short clock
CISA added CVE-2026-85102 and CVE-2026-93616 to its Known Exploited Vulnerabilities catalog September 22 and set a September 25 federal deadline. Both carry CVSS scores of 9.8. Under BOD 26-04, agencies must conduct forensic triage as well as apply fixes—a signal that CISA is concerned some environments may already be compromised.
What each vulnerability exposes
CVE-2026-85102 involves improper certificate validation during IKEv2 VPN negotiation and can enable unauthenticated code execution on affected Security Gateway and Spark appliances using site-to-site or remote-access VPN. CVE-2026-93616 is a pre-authentication path-traversal and file-upload flaw in the Security Management Server web service, which can allow arbitrary scripts to run in the system that controls policies, logs and gateways.
The exploitation timeline
Check Point reported exploitation attempts against Spark customers beginning September 12 and a handful of targeted zero-day attempts involving the management flaw as early as July 23. Fixes shipped September 9 in advisories sk1000117 and sk1000118; R82.20 was reported unaffected. The Dutch NCSC had warned that exploitation of the gateway issue was likely.
Why patching alone is inadequate
If an attacker reached a management server before it was fixed, installing the update does not remove persistence, restore trustworthy logs or rotate exposed credentials. Security teams need to identify suspicious uploads and processes, preserve evidence, check managed gateways and review administrative changes. A clean version number answers whether the door is closed now, not whether somebody entered earlier.
Who is exposed and what comes next
Federal agencies are directly bound by the deadline, but enterprises and managed-security providers face the same technical risk. Internet-facing management planes and VPN gateways deserve priority. Incident-response vendors benefit from emergency demand; affected operators bear outage and investigation costs. The next public test is whether exploitation remains targeted or expands into mass ransomware activity—and whether post-incident reviews reveal compromises that patch-only programs missed.
Related Signal Post News coverage
the separate TeamCity ransomware warning the limits and promise of security automation
Sources and reporting basis
- securityaffairs.com reporting
- www.rescana.com reporting
- gbhackers.com reporting
- securityarsenal.com reporting
Reporting note: This is a fixed September 25, 2026 snapshot. Attributed claims remain attributed; forecasts, polls, vendor results and early cyber findings can change as new evidence appears.