Skip to main content
Defentria

Vulnerabilities

Check Point warns of attacks on its Spark firewalls for SMEs through a VPN flaw

Check Point confirms that a critical flaw in its firewalls' VPN, fixed on 9 September, has been exploited since 12 September against customers of Spark, its range for small and medium-sized businesses. If your company has a Check Point, it's time to confirm it's up to date.

By Defentria editorial teamPublished 3 min read

Check Point — Vendor of the affected product (Security Gateway and Spark firewalls)

Close-up of an Ethernet network port on an adapter resting on a table
Image: Jesse Ayegba on Unsplash (Unsplash License)

In 30 seconds

  • Check Point confirms that flaw CVE-2026-85102, in its firewalls' VPN, lets an attacker with no credentials run code on the device. Its severity is 9.8 out of 10.
  • The fix has been available since 9 September; according to Check Point, the attacks began on 12 September and target customers of Spark, its range for SMEs.
  • CISA added it to its catalogue of actively exploited vulnerabilities on 22 September.
  • It affects devices with remote access VPN or site-to-site VPN. Updating closes the door, but it's also worth checking whether someone has already got in.

Does this affect me?

It affects you if your company has a Check Point firewall (a Spark or a Security Gateway) with VPN enabled, whether for remote working or to connect offices, and the fix released on 9 September hasn't been installed. If you don't use Check Point, this news doesn't affect you directly, although the lesson applies to any firewall. No Spanish victims have been confirmed.

What happened

On 22 September 2026, Check Point published a security advisory titled "Action Required" about two exploited vulnerabilities in its products. The one that matters most to SMEs is CVE-2026-85102: according to the vendor, "improper validation of certificate data during VPN negotiation allows unauthenticated remote code execution". In other words, an attacker can take control of the firewall without knowing any password.

Check Point released the fix on 9 September. Three days later, on 12 September, it began to observe exploitation attempts aimed, according to its advisory, at Spark customers worldwide. Spark is the firewall range that Check Point presents as designed for SMEs and for the service providers that manage them.

On that same 22 September, the US cybersecurity agency (CISA) added the vulnerability to its catalogue of actively exploited flaws (KEV).

What we know

  • Severity: Check Point gives it a CVSS score of 9.8 out of 10.
  • Affected devices (according to Check Point): Security Gateway and Spark firewalls, both locally and centrally managed, in versions R81, R81.10, R81.10.X, R81.20, R82, R82.00.X and R82.10. R81 and R81.10 are no longer supported.
  • When it's vulnerable: when the device has remote access VPN (the one employees use to work remotely) or site-to-site VPN enabled.
  • How it's attacked: Check Point says the attempts come from anonymisation services, such as commercial VPNs and proxy networks, and that once inside, attackers often scan the internal network.
  • A second flaw: the same advisory covers CVE-2026-93616, which affects Check Point's management server. The vendor saw "a handful of pinpointed attacks" on 23 July. According to Check Point, it only affects its management products (Security Management), which are more typical of large installations.

What we don't know yet

  • How many companies have been attacked or compromised. Check Point gives no figures.
  • Who is behind the attacks.
  • Whether there are victims in Spain. None have been confirmed.

Why it matters

It's the same pattern we saw a few days ago with FortiGate: the device that guards the network's entrance becomes the way in. This time with one difference: the vendor explicitly says the attacks target its SME range. And the gap between the fix and the first attacks was just three days.

What it means for an SME

A Check Point Spark firewall usually arrives at a company through the IT provider, who configures it, enables the VPN so the team can work remotely and often never touches it again. That VPN is exactly what's being attacked.

If nobody in your company knows for sure which firewall you have, who updates it or when it was last updated, that's not a technical problem: it's a problem of unassigned responsibilities.

What your company should do this week

  1. Ask your IT provider whether you have a Check Point firewall and whether its VPN is enabled.
  2. If the answer is yes, ask them to confirm in writing that the fix Check Point released on 9 September is installed (its support reference is sk1000117).
  3. Ask them to review VPN access since 12 September. Check Point recommends looking for anomalous certificate-based logins and suspicious follow-up activity, such as internal network scans. Updating doesn't remove anyone who already got in.
  4. If it's a Security Gateway on R81 or R81.10, Check Point no longer supports them: ask for a plan to migrate to a supported version.
  5. Put in writing who updates the firewall and how often. If nobody has been assigned the task, nobody does it.

If you're not sure which of your company's devices are exposed to the internet, a cybersecurity audit is the place to start.

Sources

  1. Check Point — «Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616» (22 September 2026)Primary source
  2. CISA — four vulnerabilities added to the KEV catalogue (22 September 2026)Primary source
  3. Truesec — «CVE-2026-85102 & CVE-2026-93616: Active Exploitation of Check Point Security Gateway and Security Management Vulnerabilities» (25 September 2026)

Defentria editorial team. The Defentria team selects cybersecurity news from primary sources (CERTs, official bodies and vendors) and explains what it means for a Spanish SME and what to do about it.