Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Check Point Addresses Management Server Zero-Day Exploit

Check Point Addresses Management Server Zero-Day Exploit

Posted on September 22, 2026 By CWS

On July 23, a zero-day vulnerability in Check Point’s Security Management Server was exploited in several targeted attacks. This vulnerability, identified as CVE-2026-93616, permits attackers with access to the server’s web service to execute scripts without authentication. Check Point has since released a patch on September 22 to address this issue, which affects the server responsible for managing firewall policies for its gateways.

Details of the Exploited Vulnerability

The flaw CVE-2026-93616 is characterized as a path traversal bug within the management server’s web service, failing to adequately restrict file and folder access. This allows potential attackers to upload and execute scripts on the server. The vulnerability received a severity score of 9.8 out of 10 on the CVSS scale, highlighting its critical nature. However, details regarding the specific targets or the attackers involved have not been disclosed by Check Point.

Patch and Mitigation Guidance

Check Point’s advisory specifies the affected versions, which include several releases such as R82.20 without a Jumbo Hotfix, among others. Administrators are advised to verify their server’s version and install the necessary updates from support article sk1000171. Additionally, Check Point provides guidance on detecting indicators of compromise and recommends vigilance even after installing the patch, as it does not indicate if prior exploitation occurred.

Another vulnerability, CVE-2026-91843, was also patched by Check Point through its LivePatch channel on September 16, yet it does not remedy CVE-2026-93616. Administrators must ensure comprehensive updates to secure their systems.

Ongoing Security Challenges

Further attempts to exploit another vulnerability, CVE-2026-85102, have been observed. This VPN-related flaw, fixed earlier on September 9, targets Check Point’s Spark firewall line for small businesses. It affects both gateways and management servers. Check Point advises monitoring for unusual certificate-based VPN logins and provides workarounds for unpatched gateways, as detailed in support article sk1000117.

According to Check Point, the exploit attempts originate from anonymized infrastructures, utilizing VPN services and proxies with specific certificate subjects. Administrators are encouraged to scrutinize logs for anomalous activity that may indicate exploitation attempts.

Future Security Outlook

As cyber threats continue to evolve, maintaining up-to-date security measures remains crucial. Check Point’s swift response and detailed advisories underscore the importance of timely patch management and threat monitoring. Organizations are urged to follow Check Point’s guidance closely, ensuring their systems are fortified against potential attacks.

The Hacker News Tags:Check Point, CVE-2026-93616, Cybersecurity, Exploit, Firewalls, network security, security patch, VPN, Vulnerability, zero-day

Post navigation

Previous Post: Critical Flaw in Check Point Servers Actively Exploited
Next Post: Aembit Integrates Okta’s Cross App Access for AI Control

Related Posts

3,000 YouTube Videos Exposed as Malware Traps in Massive Ghost Network Operation 3,000 YouTube Videos Exposed as Malware Traps in Massive Ghost Network Operation The Hacker News
Researcher Found Flaw to Discover Phone Numbers Linked to Any Google Account Researcher Found Flaw to Discover Phone Numbers Linked to Any Google Account The Hacker News
Why Critical Infrastructure Needs Stronger Security Why Critical Infrastructure Needs Stronger Security The Hacker News
Critical Cisco SD-WAN Vulnerability Exploited Since 2023 Critical Cisco SD-WAN Vulnerability Exploited Since 2023 The Hacker News
DoJ Cracks Down on SE Asia Crypto Scams, .8M Frozen DoJ Cracks Down on SE Asia Crypto Scams, $3.8M Frozen The Hacker News
LangSmith Bug Could Expose OpenAI Keys and User Data via Malicious Agents LangSmith Bug Could Expose OpenAI Keys and User Data via Malicious Agents The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Aembit Integrates Okta’s Cross App Access for AI Control
  • Check Point Addresses Management Server Zero-Day Exploit
  • Critical Flaw in Check Point Servers Actively Exploited
  • BigCommerce Faces Data Breach Through Ribon Apps
  • Microsoft Dismantles AI-Powered Phishing Network EvilTokens

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Aembit Integrates Okta’s Cross App Access for AI Control
  • Check Point Addresses Management Server Zero-Day Exploit
  • Critical Flaw in Check Point Servers Actively Exploited
  • BigCommerce Faces Data Breach Through Ribon Apps
  • Microsoft Dismantles AI-Powered Phishing Network EvilTokens

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark