Federal cybersecurity authorities have expanded the Known Exploited Vulnerabilities catalog to mandate remediation for two security flaws in perimeter firewall appliances. Unauthenticated remote actors actively exploit certificate validation flaws and path traversal errors to compromise security gateways.
The catalog additions cover improper certificate validation vulnerability CVE-2026-85102 and path traversal vulnerability CVE-2026-93616 affecting Check Point Security Gateway and Spark Firewall product lines. Unauthenticated remote adversaries transmit malformed network packets over site-to-site VPN connections or web portals to bypass authentication controls, read arbitrary configuration files, and execute operating system commands. CISA mandated federal civilian agency patching under Binding Operational Directive 26-04 with a September 25 compliance deadline.
Subverting perimeter security gateways undermines corporate network access controls. Possessing unauthenticated command execution or arbitrary file access rights over perimeter firewall appliances allows threat actors to capture unencrypted network traffic, extract VPN credential stores, and pivot into internal enterprise subnets.
– Apply official security hotfixes published by Check Point across all Security Gateway and Spark Firewall appliances immediately.
– Restrict public internet visibility of firewall management interfaces and web portals using strict access control policies.
– Inspect firewall system access logs for anomalous path traversal sequences or unverified certificate validation events.
– Invalidate active remote access VPN session tokens and rotate administrative certificates across managed gateway fleets.
Perimeter firewall security depends on rigid input validation and prompt security hotfix deployment to guarantee security gateways remain protected from active wild exploitation pipelines. #CodeDefence #CheckPoint #Firewall #CISA #KEV #NetworkSecurity #AuthBypass #PatchManagement
/
