A firewall vulnerability rated 9.8 out of 10 was patched by Check Point on September 9. There was no confirmed attack at the time, just a warning from the Dutch government’s cyber security centre that exploitation looked imminent. On September 22, CISA confirmed it, and added a second Check Point flaw alongside it. That two week gap between disclosure and confirmed exploitation is the whole story here, and it says more about patch timing than about any one vendor.

What This Firewall Vulnerability Actually Does

Check Point actually shipped two separate patches on September 9, for two different vulnerabilities on two different parts of its product line.Check Point actually shipped two separate patches on September 9, for two different vulnerabilities on two different parts of its product line.

CVE-2026-85102 is the flaw in the Security Gateway itself, the device handling live VPN traffic. It’s a flaw in how the gateway validates certificates during VPN negotiation. Get past that check and an unauthenticated attacker can run code directly on the gateway, no login required.

CVE-2026-93616 sits somewhere different: the Security Management Server, the console that controls policy, logs, and configuration across a Check Point deployment (also affects Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent). It’s a path traversal flaw that lets an unauthenticated attacker upload and execute arbitrary scripts on the management server, fixed separately through Check Point’s R82.20 Security Hotfix, not the same patch that covers the gateway flaw.

That distinction matters operationally. Patching the gateway doesn’t patch the management server, and vice versa. A business running Check Point needs to confirm both planes are current, not just one.

Check Point found and disclosed both issues itself, and shipped fixes the same day. No evidence of active exploitation at the time of disclosure. By September 12, Check Point had started observing exploitation attempts against Spark firewall customers using anonymizing infrastructure. By September 22, CISA had confirmed active exploitation of both and added them to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of September 25, as SecurityAffairs reported.

Timeline showing Check Point's two September 9 patches, gateway and management server, confirmed under active exploitation by CISA September 22.

The same week, CISA added two more network edge products to its confirmed exploited list: a flaw in Arista’s VeloCloud Orchestrator, and one in F5’s BIG-IP APM. Four vulnerabilities, three vendors, one week, the same lesson each time. Attackers probe internet facing network gear first, because it’s the thing standing between them and everything behind it.

Why This Matters for a Small or Midsize Business?

These aren’t obscure enterprise products. Firewalls, VPN gateways, and the management consoles that control them are exactly what a small business relies on to guard its perimeter, often without a dedicated security team watching vendor bulletins day to day. A firewall vulnerability like this doesn’t need an employee to click a link or fall for a phishing email. It just needs the device to be reachable and unpatched.

The Real Gap Isn’t the Vendor, It’s the Patch Window

Check Point did everything right here. Found both issues itself, disclosed them, shipped fixes the same day, no delay. The businesses at risk right now aren’t the ones using Check Point. They’re the ones still running the unpatched build two weeks later, whether or not anyone on staff knew a patch existed, or knew there were two patches to apply instead of one.

That’s true of any vendor, not just this one. A 9.8 severity rating is urgent the day it’s published, not the day it shows up on a government watchlist.

Four-step checklist for VPN and firewall patch management, including verifying Check Point's gateway and management server patches separately.

What to Check This Week?

  • Confirm perimeter devices, firewalls, VPN gateways, remote access appliances, and their management consoles, are on the vendor’s current patched build, not just “up to date” by whatever definition IT last used.
  • If you run Check Point, verify both patches separately. The gateway fix and the management server fix are not the same update.
  • Don’t wait for a CISA KEV listing to treat a critical severity rating as urgent. By the time it’s confirmed exploited, the window has already closed for some businesses.
  • Check whether patch management is actually tracked somewhere, or whether it depends on someone noticing a vendor bulletin. If it’s the second one, that’s the actual finding from this week, not the CVE number.

If patching your perimeter isn’t something you can say with confidence is centrally tracked and verified across every device and every console, that’s worth a conversation before the next firewall vulnerability lands. Managed IT services that includes patch management as a standing part of the job closes exactly this kind of gap. It’s the same problem covered in what to ask your MSP about their own security, just from the vendor side this time.