VMTech
Discuss a project

Check Point patches exploited Security Management Server flaw

Check Point patches exploited Security Management Server flaw

Check Point has released a fix for CVE-2026-93616, a critical path traversal vulnerability in its Security Management Server that was exploited in a handful of targeted attacks on July 23. The flaw has a CVSS score of 9.8 and can allow an attacker able to reach the server’s web service to upload and execute scripts without logging in.

The September 22 update is significant because Security Management Server controls firewall policies for the Check Point gateways it manages. Check Point did not identify the organisations targeted in July, the attackers involved, or activity performed after exploitation.

Versions and patch status require close checking

The vulnerable web service does not properly restrict the files and directories a request can access. This enables an attacker to use path traversal to place scripts on the server and run them. The CVE record lists R82.20 with no Jumbo Hotfix, R82.10 through Jumbo Hotfix Take 44, R82 through Take 126, R81.20 through Take 166, and R81.10 through Take 190 as affected. R81.10 is end of support, as are R81, R80.40, R80.30, R80.20, R80.10 and R80.

Check Point numbers Jumbo Hotfix releases by “Take”, while LivePatch uses separate take numbers. A LivePatch fix issued on September 16 for CVE-2026-91843, identified as Take 28 or Take 29 for R82.20, does not fix CVE-2026-93616. On R82.10, R82 and R81.20, the new vulnerability’s affected range extends one Take beyond the range for the earlier VPN certificate flaw, so an installation updated only to clear that issue can remain exposed.

The broader pattern of attackers exploiting security infrastructure vulnerabilities is also reflected in incident reporting on infrastructure vulnerability exploitation, where incident reporting shows how quickly patch and detection priorities can change. For this issue, Check Point directs administrators to support article sk1000171 for fixed builds, mitigation guidance, hunting instructions and indicators of compromise.

VPN exploitation attempts also target Spark firewalls

Check Point separately said that attackers have attempted to exploit CVE-2026-85102 since September 12. The VPN certificate validation flaw, fixed on September 9, may allow an unauthenticated attacker to execute code on an affected gateway during VPN setup. It affects Security Gateway and Spark firewalls, whether centrally or locally managed, across R81, R81.10, R81.10.x, R81.20, R82, R82.00.x and R82.10; R81 and R81.10 are end of support.

The Netherlands’ National Cyber Security Centre says exposure to CVE-2026-85102 depends on use of Site-to-Site VPN or Remote Access VPN. Check Point said the observed attempts used anonymising infrastructure, including VPN services and proxies, and certificates bearing subjects such as CN=vpn, OU=users, O=global. The vendor cautioned that this list is incomplete and advised reviewing unusual certificate-based Mobile Access logins and subsequent activity, including internal port and service scanning.

Operational priority for administrators

Administrators should compare every management server’s release and Jumbo Hotfix Take with the affected list, install the build specified in sk1000171, and use the supplied indicators to investigate potential activity. Installing the fix does not determine whether a server was compromised before patching. For CVE-2026-85102, customers that installed the September 9 fix are protected; organisations unable to patch Site-to-Site VPN immediately can restrict UDP ports 500 and 4500 to named peer IP addresses, although that workaround does not apply to locally managed Spark firewalls. The practical implication is to treat patch verification and retrospective log review as separate tasks for both management servers and VPN gateways.

#cybersecurity#vulnerability#firewallsecurity#patchmanagement
Open analytics
On the site 0 views
min read 4 22.09.2026
Instagram

Check Point patches exploited Security Management Server flaw

Open the post on Instagram ↗