On July 23, a zero-day vulnerability in Check Point’s Security Management Server was exploited in several targeted attacks. This vulnerability, identified as CVE-2026-93616, permits attackers with access to the server’s web service to execute scripts without authentication. Check Point has since released a patch on September 22 to address this issue, which affects the server responsible for managing firewall policies for its gateways.
Details of the Exploited Vulnerability
The flaw CVE-2026-93616 is characterized as a path traversal bug within the management server’s web service, failing to adequately restrict file and folder access. This allows potential attackers to upload and execute scripts on the server. The vulnerability received a severity score of 9.8 out of 10 on the CVSS scale, highlighting its critical nature. However, details regarding the specific targets or the attackers involved have not been disclosed by Check Point.
Patch and Mitigation Guidance
Check Point’s advisory specifies the affected versions, which include several releases such as R82.20 without a Jumbo Hotfix, among others. Administrators are advised to verify their server’s version and install the necessary updates from support article sk1000171. Additionally, Check Point provides guidance on detecting indicators of compromise and recommends vigilance even after installing the patch, as it does not indicate if prior exploitation occurred.
Another vulnerability, CVE-2026-91843, was also patched by Check Point through its LivePatch channel on September 16, yet it does not remedy CVE-2026-93616. Administrators must ensure comprehensive updates to secure their systems.
Ongoing Security Challenges
Further attempts to exploit another vulnerability, CVE-2026-85102, have been observed. This VPN-related flaw, fixed earlier on September 9, targets Check Point’s Spark firewall line for small businesses. It affects both gateways and management servers. Check Point advises monitoring for unusual certificate-based VPN logins and provides workarounds for unpatched gateways, as detailed in support article sk1000117.
According to Check Point, the exploit attempts originate from anonymized infrastructures, utilizing VPN services and proxies with specific certificate subjects. Administrators are encouraged to scrutinize logs for anomalous activity that may indicate exploitation attempts.
Future Security Outlook
As cyber threats continue to evolve, maintaining up-to-date security measures remains crucial. Check Point’s swift response and detailed advisories underscore the importance of timely patch management and threat monitoring. Organizations are urged to follow Check Point’s guidance closely, ensuring their systems are fortified against potential attacks.
