Check Point said attackers used a zero-day flaw, CVE-2026-93616, to target Security Management Servers in limited attacks on July 23, and the company later released fixes and hunting guidance. Separately, attackers have been trying to exploit CVE-2026-85102 in Spark firewalls and gateways through VPN connections since September 12, using anonymizing infrastructure and suspicious certificates. #CVE-2026-93616 #CVE-2026-85102 #CheckPoint
Keypoints
- CVE-2026-93616 is a path traversal flaw in Check Point Security Management Server web service.
- The bug can let an attacker upload and run scripts without logging in.
- Check Point says the flaw was used in targeted attacks on July 23.
- CVE-2026-85102 affects VPN certificate handling in Check Point gateways and Spark firewalls.
- Check Point says exploitation attempts against CVE-2026-85102 began on September 12 using VPNs and proxies.
Read More: https://thehackernews.com/2026/09/check-point-warns-of-management-server.html