Check Point has warned customers about attacks exploiting two vulnerabilities in its firewall and management products. In a September 22 advisory, the company said fixes were available for both and urged affected users to install them immediately.
The gateway flaw, CVE-2026-85102, affects VPN certificate handling. Check Point released its fix on September 9 and says it observed exploitation attempts against Spark customers beginning September 12.

The separate management flaw, CVE-2026-93616, received a fix with the September 22 advisory. Check Point says it observed a handful of targeted attacks on July 23. The vendor assigns both vulnerabilities a CVSS severity score of 9.8 out of 10.
Customers should consult the linked vendor advisory for affected products and the applicable support notices before choosing a fix.
