Check Point Zero-Day Exploited in Attacks Against Firewalls and Management Servers

Check Point has released emergency security fixes for two critical vulnerabilities actively exploited against its firewall and management products. The flaws, tracked as CVE-2026-85102 and CVE-2026-93616, both carry CVSS severity scores of 9.8 and can be exploited before authentication.

CVE-2026-85102 affects certificate handling during VPN negotiations. Successful exploitation could allow an unauthenticated attacker to execute malicious code remotely on Check Point Security Gateway and Spark Firewall appliances. Check Point originally patched the vulnerability on September 9, 2026, but later detected a global wave of exploitation attempts targeting Spark customers.

The second flaw, CVE-2026-93616, is a newly disclosed zero-day affecting the Check Point Security Management web service. Attackers can exploit the path-traversal vulnerability to execute scripts from arbitrary locations and load malicious Java classes. Check Point said it observed a small number of targeted attacks exploiting the flaw on July 23.

These vulnerabilities present a serious risk because firewalls, VPN gateways and security-management servers occupy trusted positions within corporate networks. Compromising one of these systems could help an attacker access internal services, scan the network, alter security configurations or establish a foothold for further attacks.

Organizations running affected Check Point products should install the appropriate Jumbo Hotfix or vendor-provided update immediately. Administrators should verify that every appliance received the correct fix and review logs for suspicious certificate-based Mobile Access logins, unfamiliar users and internal port-scanning activity. Check Point warns that LivePatch Takes 28 and 29 do not fix CVE-2026-93616, making it important to follow the product-specific remediation instructions.

Check Point has not publicly identified the attackers or confirmed how many customers were successfully compromised. However, the confirmed exploitation and the privileged position of affected systems make these vulnerabilities an urgent patching priority for enterprise defenders.

Leave a Comment

Your email address will not be published. Required fields are marked *