Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Target Critical VPN Flaws in Check Point Systems

Hackers Target Critical VPN Flaws in Check Point Systems

Posted on September 24, 2026 By CWS

Hackers are actively exploiting significant vulnerabilities in Check Point’s VPN and management products, posing a risk of unauthorized remote access and potential remote code execution. These vulnerabilities, identified as CVE-2026-85102 and CVE-2026-93616, have been assigned a critical CVSS severity score of 9.8, prompting Check Point to release urgent patches.

Details of the Vulnerabilities

The first vulnerability, CVE-2026-85102, affects Check Point Security Gateway and Spark Firewall systems using Remote Access VPN or certificate-based Site-to-Site VPN authentication. The flaw arises from inadequate validation of certificate data during VPN negotiations, which could allow attackers to execute arbitrary code without valid credentials. Although Check Point provided a patch on September 9, 2026, exploitation attempts were observed starting September 12, targeting Spark Firewall customers worldwide.

Attackers utilizing this flaw have been using suspicious VPN certificate subjects, though these should not be considered exhaustive. Threat actors may alter certificate subjects in future attacks to evade detection.

Newly Disclosed Zero-Day Threat

The second vulnerability, CVE-2026-93616, is a newly discovered zero-day flaw affecting Check Point’s Security Management and Multi-Domain Security Management environments. It involves a pre-authentication directory traversal and file-upload issue, enabling attackers to upload and execute arbitrary scripts on vulnerable management servers. Check Point has confirmed several real-world attacks targeting this flaw.

This vulnerability affects several Check Point products, including Security Management Server and Multi-Domain Security Management Server. However, Smart-1 Cloud, Check Point Firewall Appliances, and Check Point Spark Firewall are not impacted by this issue.

Mitigation Measures

Organizations using susceptible Check Point products are urged to immediately apply the recommended security patches. For CVE-2026-85102, the LivePatch Take 26 or later Jumbo Hotfix releases offer protection, while for CVE-2026-93616, the R82.20 Security Hotfix or supported Jumbo Hotfix versions are recommended.

Administrators should also monitor Mobile Access logs for unusual VPN login activities and investigate any suspicious actions by newly authenticated users. Internal port scanning or unexpected service discovery following questionable VPN logins could indicate further intrusion attempts. Check Point advises restricting TCP port 19009 access to trusted IP addresses to safeguard management servers.

The active exploitation of these vulnerabilities underscores the critical importance of promptly patching internet-facing VPN and security-management infrastructures. Failure to do so could leave systems vulnerable to exploitation by ransomware operators, access brokers, and state-sponsored threat actors.

Cyber Security News Tags:Check Point, CVE-2026-85102, CVE-2026-93616, Cybersecurity, Exploit, Firewall, network security, Ransomware, remote access, security patch, Threat Actors, VPN, Vulnerabilities, zero-day

Post navigation

Previous Post: Unpatched Vulnerabilities in OnePlus Phones Pose Risks
Next Post: AI Search Poisoning and Security Risks: Key Cyber News

Related Posts

Stealthy Windows Backdoor Evades Detection Until Triggered Stealthy Windows Backdoor Evades Detection Until Triggered Cyber Security News
Ransomware Group Rapidly Disables Security and Encrypts Networks Ransomware Group Rapidly Disables Security and Encrypts Networks Cyber Security News
Google Vulnerability Let Attackers Access Any Google User Phone Number Google Vulnerability Let Attackers Access Any Google User Phone Number Cyber Security News
New Beast Ransomware Actively Scans for Active SMB Port from Breached System to Spread Across Network New Beast Ransomware Actively Scans for Active SMB Port from Breached System to Spread Across Network Cyber Security News
Python-based PyRAT with Cross-Platform Capabilities and Extensive Remote Access Features Python-based PyRAT with Cross-Platform Capabilities and Extensive Remote Access Features Cyber Security News
CISA Alerts on VMware ESXi Vulnerability in Ransomware CISA Alerts on VMware ESXi Vulnerability in Ransomware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SCOUTz Launches Beta for MSPs with New Intelligence Platform
  • AI Search Poisoning and Security Risks: Key Cyber News
  • Hackers Target Critical VPN Flaws in Check Point Systems
  • Unpatched Vulnerabilities in OnePlus Phones Pose Risks
  • Urgent Update: Roundcube Webmail SQL Flaw Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SCOUTz Launches Beta for MSPs with New Intelligence Platform
  • AI Search Poisoning and Security Risks: Key Cyber News
  • Hackers Target Critical VPN Flaws in Check Point Systems
  • Unpatched Vulnerabilities in OnePlus Phones Pose Risks
  • Urgent Update: Roundcube Webmail SQL Flaw Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark