Connect with us

Cybersecurity

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Published

on

Check Point has disclosed an actively exploited vulnerability in its Security Management Server, warning customers that attackers used the previously unknown flaw in targeted attacks before a fix became available.

Tracked as CVE-2026-93616, the critical vulnerability can allow an unauthenticated attacker with access to the server’s web service to upload and execute scripts remotely. Check Point released security updates for the flaw on September 22, 2026.

Critical Security Management Server Vulnerability

CVE-2026-93616 is a path traversal vulnerability affecting the web service of Check Point Security Management Server.

The flaw results from insufficient restrictions on the files and directories that can be accessed through specially crafted requests. Attackers can potentially abuse the weakness to upload malicious scripts and execute them on the affected management server.

Check Point assigned the vulnerability a CVSS score of 9.8 out of 10, placing it in the critical severity category.

The company said the vulnerability was exploited in a small number of targeted attacks on July 23. However, its advisory does not identify the attackers or organizations targeted, nor does it disclose what actions the attackers performed after gaining access.

Which Versions Are Affected?

According to the vulnerability information, affected versions include several supported and end-of-support releases of Security Management Server.

Potentially vulnerable configurations include:

  • R82.20 without the required Jumbo Hotfix
  • R82.10 with Jumbo Hotfix Take 44 or earlier
  • R82 with Take 126 or earlier
  • R81.20 with Take 166 or earlier
  • R81.10 with Take 190 or earlier
  • Older R81 and R80.x releases that have reached end of support

Administrators should verify both the Security Management Server release and installed Jumbo Hotfix level before determining whether their systems are protected.

Check Point has published fixed builds, mitigation instructions and indicators of compromise through its security support documentation.

Patch Installation and Threat Hunting Recommended

Check Point is urging administrators to take immediate action rather than assuming that installing the latest update alone proves a system was never compromised.

Organizations should first identify their server version and Jumbo Hotfix level, then install the appropriate security update.

Security teams should also review the indicators of compromise and threat-hunting guidance provided by Check Point. This is particularly important because systems may have been attacked before the vulnerability was patched.

The company previously released another management-server security update in September for CVE-2026-91843. Check Point has clarified that the LivePatch updates addressing that vulnerability do not protect against CVE-2026-93616.

Separate VPN Vulnerability Also Under Attack

Check Point has also reported active exploitation attempts involving a separate vulnerability, CVE-2026-85102, affecting its VPN functionality.

The company released patches for that flaw on September 9. At the time of the initial disclosure, Check Point said it had no evidence that the vulnerability was being exploited.

However, exploitation attempts were detected beginning September 12, particularly against customers using Check Point Spark firewalls designed for smaller businesses.

CVE-2026-85102 involves the way Check Point gateways process certificates during VPN connection establishment. Under certain conditions, an unauthenticated attacker could potentially execute code on an affected gateway.

Attackers Used Anonymizing Infrastructure

According to Check Point, the recent exploitation attempts originated through anonymizing services, including VPN providers and proxy infrastructure.

Investigators observed certificates associated with several certificate subjects, including:

  • CN=vpn,OU=users,O=global
  • CN=vpn-user,OU=users,O=global
  • CN=vpnuser,OU=users,O=global

Check Point cautioned that this list may not represent all certificates used by attackers.

Security teams should therefore examine logs for unusual certificate-based Mobile Access activity rather than relying exclusively on the listed certificate subjects.

Administrators should also investigate suspicious activity following VPN authentication, including attempts to scan internal ports and network services.

Guidance for Unpatched VPN Systems

Check Point says customers who installed the September 9 security update for CVE-2026-85102 are protected against the vulnerability.

For systems that cannot immediately be patched, the Netherlands’ National Cyber Security Centre has published a mitigation approach for certain Site-to-Site VPN configurations.

The workaround involves disabling implied VPN rules and restricting UDP ports 500 and 4500 to approved peer IP addresses. However, the mitigation does not apply to locally managed Spark firewalls.

Organizations using affected Check Point products should follow the vendor’s official mitigation and patching guidance for their specific configuration.

Security Teams Face Two Active Threats

The simultaneous disclosure of an actively exploited Security Management Server vulnerability and exploitation attempts against a separate VPN flaw highlights the importance of reviewing Check Point deployments for both vulnerabilities.

Administrators should prioritize patching supported systems, investigate historical logs for suspicious activity and review available indicators of compromise.

Because the management-server vulnerability was exploited before its public disclosure, organizations should conduct threat hunting even after applying the security update.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2026 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO