Have questions? Speak to our experts at 8447712333 Connect With Us
Two Check Point Zero-Days, Two Opposite Lessons About Patch Timing

Two Check Point Zero-Days, Two Opposite Lessons About Patch Timing

innovativeacademy

innovativeacademy

September 29, 2026

Two Check Point Zero-Days, Two Opposite Lessons About Patch Timing

1. Introduction

Most write-ups about a critical vulnerability focus on one number—the CVSS score—and one instruction—patch now. Check Point's mid-September 2026 advisory is worth a closer look because it brings together two separate flaws, both scored 9.8, that were exploited on entirely different timelines.

One vulnerability was quietly weaponized for roughly two months before public disclosure. The other went from patch release to observed exploitation attempts in just three days.

Those timelines do not teach exactly the same lesson. Looking at them together shows why organizations need both rapid patching and proactive investigation for signs of earlier compromise.

2. What Actually Happened: One Advisory, Two Separate Flaws

Check Point published a joint security advisory covering CVE-2026-85102, affecting Security Gateway and Spark Firewall devices, and CVE-2026-93616, affecting Security Management Server.

Both vulnerabilities received a CVSS severity score of 9.8 and were subsequently added to CISA's Known Exploited Vulnerabilities catalog in September 2026.

The CISA entry included a September 25, 2026 remediation date for U.S. federal civilian executive branch agencies. That deadline applies specifically to that federal population and should not be interpreted as a universal legal deadline for every organization.

Despite appearing in the same advisory and carrying the same CVSS score, the vulnerabilities affect different components, are triggered differently, and followed very different exploitation timelines.

3. CVE-2026-93616: Exploited for Two Months Before Public Disclosure

CVE-2026-93616 affects Check Point Security Management Server. The vulnerability involves a pre-authentication directory traversal and file-upload issue in the management web service.

The flaw can allow an unauthenticated attacker to execute a script from an arbitrary path and load an arbitrary Java class, potentially resulting in remote compromise of the management system.

Check Point's research traced exploitation back to attacks first observed on July 23, 2026—roughly two months before the vulnerability and its associated patch became public.

Why the Timeline Matters

The important point is not simply that the vulnerability was severe. Attackers had already been using it before defenders outside the vendor had public information about the flaw.

That creates a situation in which patching alone may not provide a complete response. Organizations also need to investigate whether the vulnerable component was compromised before the fix became available.

4. CVE-2026-85102: Exploited Within Three Days of the Patch

CVE-2026-85102 affects Check Point Security Gateway and Spark Firewall devices. The vulnerability is related to certificate validation during VPN negotiation.

It can be remotely exploitable without authentication on affected devices where Site-to-Site or Remote Access VPN functionality is active.

Check Point released a patch for the vulnerability on September 9, 2026. By September 12, Check Point was observing exploitation attempts targeting Spark customers.

Observed activity included anonymization infrastructure and recognizable certificate subjects such as CN=vpn and CN=vpn-user.

The Three-Day Window

The timeline demonstrates how quickly attackers can respond once a vulnerability becomes public and a fix is available. A patch can reveal enough information about the affected component for attackers to investigate unpatched systems.

For a critical, remotely exploitable vulnerability, waiting for a routine maintenance cycle can therefore create unnecessary exposure.

5. Why These Two Timelines Teach Opposite Lessons

CVE-2026-93616 illustrates the danger of assuming that the absence of a public advisory means an environment has not already been targeted.

A zero-day can be exploited before defenders have a public signature, CVE entry, vendor advisory, or patch. That is why vulnerability remediation and compromise investigation should be treated as separate activities.

CVE-2026-85102 demonstrates the other side of the problem. Once a patch becomes available, the time available for organizations to respond can become very short.

  • Before disclosure: organizations may need monitoring, threat hunting, and anomaly detection because no public patch may exist.
  • After disclosure: organizations need rapid assessment and remediation because attackers can quickly study and target vulnerable systems.
  • After patching: organizations should still investigate whether exploitation occurred before the system was fixed.

Together, these cases show why both proactive threat hunting and rapid patch management matter.

6. Fixing One Does Not Fix the Other

Because both vulnerabilities appeared in the same advisory, it may be tempting to treat them as one remediation task. They are not.

The vulnerabilities affect different Check Point components and require their respective fixes. Applying the remediation for the Security Management Server vulnerability does not automatically resolve the Security Gateway or Spark Firewall VPN vulnerability.

What Organizations Should Check

  • Identify all affected Check Point Security Management Server systems.
  • Identify affected Security Gateway and Spark Firewall devices.
  • Check the installed versions against Check Point's official affected and fixed-version information.
  • Apply the appropriate remediation to each affected component.
  • Review available logs and indicators of compromise where exploitation may have occurred.
  • Document remediation separately for management and gateway infrastructure.

In other words, "we patched Check Point" is not sufficiently precise. Security teams should be able to identify exactly which vulnerable components were assessed and remediated.

7. What CISA's Deadline Actually Required

CISA's Known Exploited Vulnerabilities catalog included the affected vulnerabilities in September 2026 and specified a September 25, 2026 remediation date for U.S. federal civilian executive branch agencies.

That requirement is specific to the federal agencies covered by the applicable CISA directive process. Organizations outside that scope should not interpret September 25 as a universal statutory deadline.

However, the inclusion of actively exploited vulnerabilities in the KEV catalog is an important risk signal for security teams. Organizations that have not yet assessed their Check Point infrastructure should still verify whether affected versions remain deployed.

8. What This Means for Anyone Studying Networking or Security

This incident provides several practical lessons for people learning networking, cybersecurity, and infrastructure administration.

1. Patch Timing Matters

The three-day interval between the CVE-2026-85102 patch release and observed exploitation illustrates how quickly attackers can react to newly disclosed vulnerabilities.

2. Patching and Incident Investigation Are Different Tasks

Installing a security update addresses the vulnerable software going forward. It does not automatically establish that the system was never compromised.

3. Logs and Indicators Matter

When a vulnerability was exploited before public disclosure, security teams may need to examine historical logs and available indicators of compromise to determine whether suspicious activity occurred.

4. Networking Knowledge and Security Knowledge Overlap

Understanding VPN negotiation, certificate validation, management interfaces, authentication, network segmentation, and firewall configuration provides important context when analyzing vulnerabilities affecting network infrastructure.

9. Learning Networking and Security at Innovative Academy

Understanding a security advisory is only one part of developing practical cybersecurity skills. Learners also need opportunities to understand how network infrastructure, VPNs, firewalls, authentication, and security controls work in real environments.

At Innovative Academy, learners can explore networking and cybersecurity concepts through practical training alongside foundational networking skills.

Explore the networking and cybersecurity training programs at Innovative Academy to learn more about available courses and practical learning paths.

For learners beginning with networking fundamentals, practical training can help connect concepts such as routing, switching, network security, VPN technologies, and troubleshooting to the types of security incidents discussed in real-world advisories.

10. FAQs

Do I only need to worry about one of these two CVEs if I only use Check Point VPN devices?

Not necessarily. CVE-2026-85102 applies to affected Security Gateway and Spark Firewall devices with the relevant VPN functionality active. CVE-2026-93616 affects the Security Management Server component separately. Organizations should assess each applicable component independently.

Is it too late to act now that CISA's federal deadline has passed?

No. The September 25 date was a remediation deadline for the U.S. federal agencies covered by the applicable CISA requirement. It does not mean the underlying vulnerabilities stop being relevant after that date. Organizations that have not yet assessed or remediated affected systems should still do so.

If I patch today, does that mean I am safe from both flaws?

Applying the appropriate fixes prevents exploitation of the specific vulnerabilities on systems that have been successfully remediated. It does not by itself establish whether an attacker previously exploited the system.

This is particularly important for CVE-2026-93616 because exploitation was observed before public disclosure. Security teams should consider reviewing relevant logs and published indicators of compromise in addition to applying the fix.

Why are two vulnerabilities in the same advisory treated separately?

A security advisory can contain multiple vulnerabilities affecting different products or components. Each vulnerability can have its own affected versions, exploitation method, remediation, and indicators of compromise. Organizations should therefore map each CVE to the specific systems it affects.

11. Final Thoughts

Two vulnerabilities can appear in the same security advisory and still produce very different operational timelines.

CVE-2026-93616 demonstrates the importance of investigating potential compromise even when a vulnerability was not publicly known at the time of exploitation. CVE-2026-85102 demonstrates how quickly exploitation can begin after a vulnerability and its patch become public.

The broader lesson for network and security professionals is straightforward: patching, monitoring, and incident investigation are connected but separate security activities.

The specific CVE numbers will eventually become historical references. The more durable skill is learning to ask two questions whenever a critical vulnerability appears: How long might attackers have had access before disclosure? And how quickly might they target systems that remain unpatched after disclosure?

Share this article: