EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Check Point security advisory (AV26-902) – Update 2

Official source
EudorIA operational summary

What it means

Priority 70/100

Check Point ha rilasciato un advisory (AV26-902) che segnala vulnerabilità in diversi prodotti, tra cui Security Gateway, Spark Firewall e Security Management Server. Le vulnerabilità sono associate a CVE-2026-85102 e una vulnerabilità (CVE non riportata nella fonte), che consentono bypass dell'autenticazione e esecuzione di codice remoto. L'entità canadese raccomanda di applicare gli aggiornamenti quando disponibili.

Why it matters

Le vulnerabilità possono permettere agli attaccanti di eseguire codice remoto e bypassare l'autenticazione, mettendo a rischio la sicurezza delle infrastrutture aziendali. Le PMI italiane utilizzano spesso prodotti Check Point, rendendo questa minaccia rilevante per la protezione dei dati e della rete.

Potential operational benefits

  • Riduzione della superficie esposta alle vulnerabilità
  • Miglioramento della gestione degli accessi e della sicurezza
  • Aumento della visibilità e del controllo sulle connessioni
  • Minimizzazione del rischio di attacchi remoti
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementFirewall NGFW / IPSMonitoraggio / SIEMSegmentazione di reteHardening
AudienceITSOCCISO
Information centre

Translation in progress

Canadian Centre for Cyber Security

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Serial Number: AV26-902 Date: September 9, 2026 Updated: September 22, 2026 As of September 9, 2026, Check Point is affected by vulnerabilities in the following products: Security Gateway Multiple versions Check Point Spark Firewall using Site to Site VPN or Remote Access VPN Multiple versions Security Management Server Multiple versions Check Point Spark Firewall Multiple versions Update 1 Check Point has reported that CVE-2026-85102 and CVE-2026-93616 are being exploited in the wild. Update 2 On September 22, 2026, Cybersecurity and Infrastructure Security Agency (CISA) CVE-2026-85102 and CVE-2026-93616 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-85102 - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN CVE-2026-85103 - ASN.1 decoding heap overflow leading to a remote code execution Check Point Security Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616 CISA KEV: CVE-2026-85102 CISA KEV: CVE-2026-93616

Source
Canadian Centre for Cyber Security (Canada)
Publishing entity
Canadian Centre for Cyber Security
Entity type
National CSIRT
Area
North America · CA
Original language
en · translation in preparation
Publication
22/09/2026 22:32
MITRE ATT&CK
T1078, T1059
CVE
CVE-2026-85102, CVE-2026-93616, CVE-2026-85103
Stated country
CA
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source