Check Point warns of Zero-Day vulnerability on Management Server and attacks targeting spark firewalls
Cybersecurity vendor Check Point has issued an urgent advisory regarding two security vulnerabilities currently being actively exploited in the wild. Most critical is a Zero-Day vulnerability in the Security Management Server system, alongside ongoing attacks targeting VPN functionality on its small business firewall series.
System administrators are strongly advised to audit their environments and apply patches immediately to protect their network infrastructure.
Critical Zero-Day vulnerability in Check Point Management Server
Check Point confirmed that attackers exploited a previously unknown security flaw in the Check Point Security Management Server to execute targeted attacks on July 23.

Tracked as CVE-2026-93616, the flaw carries a critical CVSS severity score of 9.8/10. The root cause stems from a path traversal vulnerability in the management server's web service, meaning the system fails to properly restrict the files and directories that a request can access.
As a result, an unauthenticated attacker can access the web service, upload scripts, and execute them directly on the server. Because the Security Management Server is responsible for controlling firewall policies across all downstream gateways, a compromise of this server poses severe risks to the entire infrastructure.
On September 22, Check Point officially released a patch for this flaw. Currently, the vendor has not disclosed the identity of the threat actors, the specific targets involved in the July incident, or the post-exploitation activities conducted by the attackers.
Affected versions and emergency remediation guidance
Check Point manages Jumbo Hotfix updates using "Take" numbers (cumulative releases). The list of versions affected by CVE-2026-93616 includes:
R82.20: No Jumbo Hotfix installed.
R82.10: Running Jumbo Hotfix Take 44 or lower.
R82: Running Jumbo Hotfix Take 126 or lower.
R81.20: Running Jumbo Hotfix Take 166 or lower.
R81.10: Running Jumbo Hotfix Take 190 or lower (End of Support).
Older versions: R81, R80.40, R80.30, R80.20, R80.10, and R80 (all End of Support).
Important notes for administrators
Previous LivePatch updates (such as Take 28 or Take 29 released on September 16 to fix CVE-2026-91843) do not remediate CVE-2026-93616.
Servers that met the safety threshold for the VPN vulnerability CVE-2026-85103 (patched on September 9) remain vulnerable to CVE-2026-93616, as the protection baseline for the new flaw requires a higher Take version.
Recommended actions from Check Point
Immediately cross-reference your server's current version and Jumbo Hotfix Take number against the advisory list.
Immediately install the patch provided in support article sk1000171.
Use the threat-hunting guidance and Indicators of Compromise (IoC) list in document sk1000171 to audit your system. Applying the patch only prevents future exploitation; it does not determine whether the server was previously compromised.
Warning on VPN attacks targeting Spark Firewall series
In a separate announcement, Check Point reported that starting September 12, attackers began attempting to exploit a VPN vulnerability designated as CVE-2026-85102. Check Point had previously released a patch for this flaw on September 9 (at which time no active exploitation had been observed).
The primary targets of this campaign are customers utilizing Spark - Check Point's firewall series designed for small and medium-sized enterprises (SMBs).
Nature of the flaw: Originates from how Check Point gateways validate certificates during VPN connection establishment, allowing an unauthenticated attacker to execute remote code on the gateway. The issue occurs when Site-to-Site VPN or Remote Access VPN features are enabled (according to the Netherlands National Cyber Security Centre - NCSC).
Affected devices: Security Gateways and Spark firewalls (whether centrally or locally managed) running versions R81, R81.10, R81.10.x, R81.20, R82, R82.00.x, and R82.10.
Attackers frequently mask their identity behind VPN services and proxies, using certificates with Subject fields formatted as:
CN=vpn,OU=users,O=global
CN=vpn-user,OU=users,O=global
CN=vpnuser,OU=users,O=global
Administrators should inspect access logs for certificate-based Mobile Access connections exhibiting anomalous indicators, while closely monitoring post-authentication behavior of suspicious accounts (which often perform port scanning and internal service enumeration).
Mitigation and remediation
Install the patch provided in support article sk1000117 as soon as possible.
Workaround (if immediate patching is not feasible): For Site-to-Site VPN, disable implied VPN rules and restrict incoming traffic on UDP ports 500 and 4500 strictly to trusted partner IP addresses. (Note: This workaround does not apply to locally managed Spark devices.)
Both CVE-2026-93616 and CVE-2026-85102 pose significant risks to enterprise information security. Proactively reviewing access logs, verifying Take version numbers, and applying patches from official Check Point support documentation are urgent actions required to secure network infrastructure against targeted exploitation attempts.
References:













Comments