➤Summary
Brand protection software can help security and digital-risk teams maintain visibility into external threats while organizations respond to vulnerabilities affecting internet-facing infrastructure. Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution vulnerability in the VPN certificate-handling functionality of its Security Gateway products. A separate vulnerability, CVE-2026-93616, affecting the Security Management web service is also being exploited.
The incident matters primarily as an infrastructure-security issue, not as evidence of a brand impersonation campaign. However, compromised edge security infrastructure can create downstream risks for identity, remote access, internal systems, customer-facing services, and potentially the digital assets security teams monitor for signs of abuse.
What Happened With the Check Point Security Gateway Vulnerability?
Check Point disclosed CVE-2026-85102 on September 9, 2026, describing it as an improper certificate-validation vulnerability in Quantum Security Gateway. The flaw can allow an unauthenticated remote attacker to execute arbitrary code on the gateway during VPN negotiation. The vulnerability carries a CVSS 3.1 score of 9.8, classified as critical.
Check Point initially reported that it had no evidence of exploitation when the vulnerability was disclosed. That situation changed shortly afterward. The company says it observed a wave of exploitation attempts beginning September 12 against Spark customers globally, with attackers using anonymization infrastructure including VPN services and proxies.
The observed certificate subjects included:
- CN=vpn,OU=users,O=global
- CN=vpn-user,OU=users,O=global
- CN=vpnuser,OU=users,O=global
Check Point explicitly warns that these subjects represent observed activity rather than a complete list of possible indicators. Organizations should therefore avoid treating those three certificate values as an exhaustive detection rule.
A Second Check Point Vulnerability Is Also Being Exploited
The same Check Point advisory addresses CVE-2026-93616, a separate pre-authentication vulnerability affecting the Security Management web service.
According to Check Point, the flaw involves path traversal and can allow an attacker to execute a script from an arbitrary path and load an arbitrary Java class. The vulnerability was assigned a CVSS score of 9.8. Check Point says it observed a small number of targeted attacks involving this vulnerability, while exploitation dates back to July 23.
CISA added both CVE-2026-85102 and CVE-2026-93616 to its Known Exploited Vulnerabilities catalog on September 22. For federal civilian executive-branch agencies, the listed remediation deadline is September 25, 2026. CISA also encourages organizations outside the federal government to use the KEV catalog as part of risk-based vulnerability management.
Which Check Point Products and Versions Are Affected?
CVE-2026-85102 affects specific Quantum Security Gateway versions, including R81.20 with Jumbo Hotfix Take 165 or earlier, R82 with Take 125 or earlier, and R82.10 with Take 43 or earlier, according to the CVE record maintained by Check Point.
Check Point has provided fixes and mitigation guidance. Its advisory recommends applying the applicable security updates immediately. For supported gateways, the company lists LivePatch Take 26 and fixed Jumbo Hotfix releases, while Spark customers have separate fixed builds. Administrators should use the vendor’s current guidance to determine the appropriate update for their exact deployment rather than relying on a generic version comparison.
CVE-2026-93616 affects a broader set of Security Management versions, including several older end-of-support releases. This makes asset inventory particularly important for organizations operating legacy management infrastructure.
Why Active VPN Exploitation Matters to Security Teams
VPN gateways sit at a strategically important point in enterprise infrastructure. They provide remote connectivity and can mediate access between external users, remote networks, and internal services.
A pre-authentication RCE vulnerability is particularly serious because exploitation does not depend on an already authenticated legitimate user session. The potential impact therefore goes beyond a conventional application vulnerability that requires credentials or user interaction.
Security teams should consider the gateway as part of the organization’s external attack surface and investigate whether exploitation could have occurred before remediation.
Check Point recommends reviewing logs for anomalous certificate-based Mobile Access logins and investigating subsequent activity from suspicious users. The company also advises looking for follow-on internal port and service scanning associated with suspicious sessions.
This is where vulnerability management, threat intelligence, logging, identity security, and incident response need to work together.
What Security Teams Should Investigate
Organizations running affected Check Point products should not assume that applying a patch automatically proves there was no prior compromise.
A practical investigation should include:
- Identify exposed assets. Determine which Security Gateway and Security Management systems were internet-accessible and which versions were running during the exposure window.
- Confirm remediation. Verify that the appropriate LivePatch or Jumbo Hotfix has been installed and that the deployed build corresponds with Check Point’s current advisory.
- Review authentication activity. Look for anomalous certificate-based Mobile Access activity and unexpected VPN sessions.
- Investigate follow-on behavior. Check for suspicious internal scanning, unusual administrative activity, unexpected configuration changes, or other activity occurring after suspicious VPN access.
- Preserve evidence. Retain relevant gateway, authentication, management, and network logs before normal retention processes remove historical records.
- Escalate suspected compromise. If investigation identifies suspicious post-exploitation activity, treat the event as a potential security incident rather than simply a patching issue.
Check Point also provides mitigation options for environments where immediate updating is not possible, but administrators should follow the vendor’s current technical instructions rather than implementing improvised access-control changes.
Where Brand Protection Software Fits Into the Investigation
The connection between this vulnerability and brand protection software requires some precision.
CVE-2026-85102 is not a lookalike-domain vulnerability, and the Check Point advisory does not establish that the exploitation campaign involved phishing domains, brand impersonation, or fraudulent websites. Security teams should not infer domain abuse from the vulnerability alone.
The relevance appears later in the incident lifecycle.
If an organization experiences a compromise involving remote-access infrastructure, defenders may need to monitor for secondary external activity. Depending on the incident, that can include suspicious domains, credential-phishing infrastructure, impersonation websites, fraudulent support pages, or other external assets attempting to exploit trust in the affected organization.
That is where domain intelligence can complement internal security telemetry.
SpoofGuard describes its platform as monitoring lookalike domains, phishing, scams, and impersonation attacks, with monitoring that incorporates domain registrations, DNS changes, SSL certificates, and website content. These capabilities address a different layer of the security problem from vulnerability remediation.
Domain Monitoring Can Add External Context
Traditional vulnerability management answers an important question: Which systems are exposed to a known vulnerability?
Domain monitoring software addresses a different question: What external infrastructure may be targeting or impersonating the organization?
For security and brand protection teams, those datasets can become more useful when correlated with an incident.
For example, if an organization is investigating unauthorized access to remote-access infrastructure, its external monitoring program can separately look for:
- Newly registered domains resembling the corporate brand
- Typosquatting or visually similar domains
- Websites copying corporate branding
- Suspicious SSL certificates associated with brand-related domains
- Phishing pages targeting customers or employees
- Domains that change from parked or inactive states to active content
- Infrastructure associated with previously identified phishing activity
These indicators do not prove that an external domain was created by the same threat actor. Correlation can prioritize investigation, but attribution requires additional evidence.
SpoofGuard’s published material on phishing detection and fake APIs similarly illustrates how domain intelligence can provide external visibility into phishing-related activity.
Do Not Confuse Vulnerability Exploitation With Domain Spoofing
The Check Point incident also demonstrates why security teams need to distinguish several different threat categories.
A compromised VPN gateway is an infrastructure-security event.
A newly registered domain resembling the organization’s name is a domain-risk indicator.
A confirmed phishing website is a malicious-content finding.
A fake login portal collecting credentials is a credential-phishing incident.
These events can potentially become related during a broader campaign, but one does not automatically prove the others.
The same principle applies to compromised data search. Finding an organization’s credentials or data in an external source does not, by itself, establish that the material came from the Check Point vulnerability. Investigators need evidence connecting the data to a particular intrusion or exposure.
This distinction prevents threat-intelligence teams from turning correlation into unsupported attribution.
What MSSPs and SOC Teams Should Prioritize
For MSSPs and MDR providers, the incident presents a useful opportunity to combine vulnerability intelligence with external threat monitoring.
A managed service can prioritize affected Check Point assets internally while separately monitoring each client’s external brand footprint. This allows analysts to investigate two different dimensions of risk without treating them as the same incident.
A useful workflow can include:
- Identify clients operating affected Check Point products.
- Prioritize internet-exposed systems and vulnerable versions.
- Track remediation status.
- Monitor security telemetry for exploitation indicators.
- Investigate suspected post-exploitation activity.
- Monitor external domains for related brand abuse.
- Escalate confirmed phishing or impersonation findings.
- Preserve evidence and coordinate appropriate abuse reporting.
- Report vulnerability and external brand-risk findings separately.
This approach is especially useful for organizations managing multiple brands, subsidiaries, customer portals, and regional domains.
Security Checklist for the Check Point VPN RCE
Security teams responding to this incident should verify:
- Affected Check Point products and versions have been identified.
- Internet exposure has been assessed.
- Applicable vendor fixes have been applied.
- VPN and Mobile Access logs have been reviewed.
- Suspicious certificate-based sessions have been investigated.
- Follow-on internal scanning has been checked.
- Relevant logs and evidence have been preserved.
- Legacy or end-of-support systems have been identified.
- External domains associated with the organization are being monitored.
- Any confirmed phishing or impersonation findings are handled through appropriate abuse channels.
The most important point is sequencing. Patch first according to the vendor’s guidance, then investigate historical activity where exploitation may have occurred, while maintaining external visibility for secondary abuse.
Build External Visibility Around Vulnerability Response
A critical VPN vulnerability does not automatically become a brand-protection incident. But when attackers gain access to infrastructure that supports remote connectivity, organizations should consider both internal compromise risk and the possibility of subsequent external abuse.
Brand protection software can complement vulnerability management by providing visibility into domains, phishing infrastructure, impersonation, and other external indicators. It should operate alongside patch management, EDR, SIEM, MFA, identity security, network monitoring, and incident response rather than replacing them.
For organizations that want to assess their external domain exposure, SpoofGuard’s 7-day free trial provides access to its domain monitoring and brand protection capabilities, including monitoring for newly registered domains, DNS changes, SSL certificates, website content, lookalike domains, and phishing indicators. This can provide a practical starting point for evaluating external visibility alongside an existing vulnerability-management program.
Disclaimer: Spoofguard reports on publicly available threat-intelligence sources. Inclusion of an organization in an article does not imply confirmed compromise. All claims are attributed to external sources unless explicitly verified.
