In September 2026, Check Point, a leading IT security company, identified vulnerabilities in several of its products. On September 7, the company issued an advisory specifically for its Spark Firewall series. Later, on September 22, they extended the alert to include their Security Management Server products. These vulnerabilities pose significant security risks.

Check Point has confirmed in its blog that these vulnerabilities, labeled CVE-2026-85102 and CVE-2026-93616, have been actively exploited. The exploitation of CVE-2026-85102 began on September 12, 2026, while CVE-2026-93616 has been under attack since July 23, 2026. This timeline indicates that attackers have been leveraging these weaknesses for a considerable period, potentially compromising the security of various systems.

The affected products include critical network infrastructure components, impacting appliances and VPN services. Organizations relying on Check Point's solutions should urgently assess their systems and apply necessary updates to mitigate these vulnerabilities. Failure to address these risks could lead to unauthorized access and data breaches, affecting organizational security and trust.