Active exploitation of two high‑severity Check Point flaws
🔒 Check Point Research reports active exploitation of two critical vulnerabilities affecting Security Gateway and Security Management. CVE-2026-85102 (RCE during VPN certificate handling) had patches available since September 9 and is being actively probed; unpatched Spark customers are at risk. CVE-2026-93616 is a newly observed pre-authentication path traversal zero-day in Management; a fix is available now. Customers should install vendor fixes immediately and follow published mitigation and hunting guidance.
