Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Check Point Addresses Management Server Zero-Day Exploit

Check Point Addresses Management Server Zero-Day Exploit

Posted on September 22, 2026 By CWS

On July 23, a zero-day vulnerability in Check Point’s Security Management Server was exploited in several targeted attacks. This vulnerability, identified as CVE-2026-93616, permits attackers with access to the server’s web service to execute scripts without authentication. Check Point has since released a patch on September 22 to address this issue, which affects the server responsible for managing firewall policies for its gateways.

Details of the Exploited Vulnerability

The flaw CVE-2026-93616 is characterized as a path traversal bug within the management server’s web service, failing to adequately restrict file and folder access. This allows potential attackers to upload and execute scripts on the server. The vulnerability received a severity score of 9.8 out of 10 on the CVSS scale, highlighting its critical nature. However, details regarding the specific targets or the attackers involved have not been disclosed by Check Point.

Patch and Mitigation Guidance

Check Point’s advisory specifies the affected versions, which include several releases such as R82.20 without a Jumbo Hotfix, among others. Administrators are advised to verify their server’s version and install the necessary updates from support article sk1000171. Additionally, Check Point provides guidance on detecting indicators of compromise and recommends vigilance even after installing the patch, as it does not indicate if prior exploitation occurred.

Another vulnerability, CVE-2026-91843, was also patched by Check Point through its LivePatch channel on September 16, yet it does not remedy CVE-2026-93616. Administrators must ensure comprehensive updates to secure their systems.

Ongoing Security Challenges

Further attempts to exploit another vulnerability, CVE-2026-85102, have been observed. This VPN-related flaw, fixed earlier on September 9, targets Check Point’s Spark firewall line for small businesses. It affects both gateways and management servers. Check Point advises monitoring for unusual certificate-based VPN logins and provides workarounds for unpatched gateways, as detailed in support article sk1000117.

According to Check Point, the exploit attempts originate from anonymized infrastructures, utilizing VPN services and proxies with specific certificate subjects. Administrators are encouraged to scrutinize logs for anomalous activity that may indicate exploitation attempts.

Future Security Outlook

As cyber threats continue to evolve, maintaining up-to-date security measures remains crucial. Check Point’s swift response and detailed advisories underscore the importance of timely patch management and threat monitoring. Organizations are urged to follow Check Point’s guidance closely, ensuring their systems are fortified against potential attacks.

The Hacker News Tags:Check Point, CVE-2026-93616, Cybersecurity, Exploit, Firewalls, network security, security patch, VPN, Vulnerability, zero-day

Post navigation

Previous Post: Critical Flaw in Check Point Servers Actively Exploited
Next Post: Aembit Integrates Okta’s Cross App Access for AI Control

Related Posts

ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services The Hacker News
North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware The Hacker News
Open Source Faces Challenges and Evolves Open Source Faces Challenges and Evolves The Hacker News
Critical Flaw in Google Dialogflow CX Exposed Critical Flaw in Google Dialogflow CX Exposed The Hacker News
Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication The Hacker News
U.S. Secret Service Seizes 300 SIM Servers, 100K Cards Threatening U.S. Officials Near UN U.S. Secret Service Seizes 300 SIM Servers, 100K Cards Threatening U.S. Officials Near UN The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Enhancing SOC Efficiency with Threat Intelligence
  • Urgent WordPress Update Fixes Major Security Vulnerability
  • Aembit Integrates Okta’s Cross App Access for AI Control
  • Check Point Addresses Management Server Zero-Day Exploit
  • Critical Flaw in Check Point Servers Actively Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Enhancing SOC Efficiency with Threat Intelligence
  • Urgent WordPress Update Fixes Major Security Vulnerability
  • Aembit Integrates Okta’s Cross App Access for AI Control
  • Check Point Addresses Management Server Zero-Day Exploit
  • Critical Flaw in Check Point Servers Actively Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark