Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Founder Summit’s agenda revealed | TechCrunch

    September 22, 2026

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    September 22, 2026

    UN Security Council Will Get Advice on AI Risks From Tech Giants Building It

    September 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Founder Summit’s agenda revealed | TechCrunch
    • WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
    • UN Security Council Will Get Advice on AI Risks From Tech Giants Building It
    • Renewables: Grid shortages are forcing India to produce and waste green energy
    • Australia news live: Joyce says One Nation talking to Coalition about power-sharing agreement; fog causes Sydney airport delays | Australia news
    • Chinese president arrives in US with new energy leverage as war rattles global markets
    • The Guardian view on Keynes in the West End: James Graham’s latest play captures the zeitgeist | Editorial
    • Far-right activist Daniel Thomas slashes dinghy in Channel with blade while rescue worker onboard | The far right
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 22, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 22, 2026Network Security / Vulnerability

    Attackers exploited a previously unknown flaw in Check Point’s Security Management Server in a handful of targeted attacks on July 23, the company said.

    The flaw, CVE-2026-93616, allows an attacker who can access the server’s web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point gateways it manages.

    Separately, Check Point said attackers have been trying since September 12 to exploit a VPN flaw it fixed on September 9. The attempts, against a flaw tracked as CVE-2026-85102, have targeted customers of Spark, Check Point’s firewall line for small businesses. When the fix came out, Check Point had no evidence the flaw was being exploited.

    CVE-2026-93616 is a path traversal bug in the management server’s web service. The service does not properly limit which files and folders a request can reach.

    An attacker can use it to upload scripts to the server and then run them. Check Point rated it 9.8 out of 10 on the CVSS scale in the CVE record for the flaw.

    Cybersecurity

    Check Point’s advisory does not name the targets of the July attacks or the attackers, nor does it say what the attackers did after exploiting the flaw.

    Management Server Versions and Fix

    Check Point numbers the Jumbo Hotfix updates for each release by “Take.” Its LivePatch channel, which pushes urgent fixes, uses a separate set of take numbers.

    The CVE record lists these versions as affected:

    • R82.20 with no Jumbo Hotfix installed
    • R82.10 with Jumbo Hotfix Take 44 or below
    • R82 with Jumbo Hotfix Take 126 or below
    • R81.20 with Jumbo Hotfix Take 166 or below
    • R81.10 with Jumbo Hotfix Take 190 or below (end of support)
    • R81, R80.40, R80.30, R80.20, R80.10 and R80 (all end of support)

    Check Point’s advisory lists R82.20 as affected without the “no Jumbo Hotfix” condition.

    On September 16, Check Point fixed a separate flaw in the management server, CVE-2026-91843, through LivePatch. That update was LivePatch Take 28, or Take 29 on R82.20, according to a summary of Check Point’s advisory by France’s CERT Santé. Check Point says those LivePatch takes do not fix CVE-2026-93616.

    CVE-2026-85103, a VPN certificate flaw that Check Point fixed on September 9, affected both gateways and management servers. On R82.10, R82, and R81.20, the new flaw’s affected list goes one take higher than that flaw’s. So a server updated only enough to be outside that September flaw’s range is still affected by CVE-2026-93616.

    The fixed builds, and Check Point’s guidance on mitigation, hunting and indicators of compromise, are in support article sk1000171. Administrators of management servers should:

    1. Check the server’s release and Jumbo Hotfix take against the list above.
    2. Install the fix listed in sk1000171.
    3. Use the hunting guidance and indicators of compromise in sk1000171 to look for signs of an attack. Installing the fix does not show whether the server was attacked before.

    Check Point’s advisory names only Security Management as affected and does not say what network access an attacker needs. The Hacker News has asked Check Point about other affected products, the fixed builds, and the July attacks.

    Spark Firewalls Targeted Through VPN Flaw

    CVE-2026-85102 is in the way Check Point gateways check certificates while a VPN connection is being set up. It may let an attacker who has not logged in run code on the gateway. Fixes have been out since September 9 and are in support article sk1000117.

    The affected products are Security Gateway and Spark firewalls, whether centrally or locally managed, on R81 and R81.10 (both end of support), R81.10.x, R81.20, R82, R82.00.x and R82.10. The Netherlands’ National Cyber Security Centre (NCSC) says the flaw applies when these products use Site-to-Site VPN or Remote Access VPN.

    Cybersecurity

    Check Point said the attempts came from anonymizing infrastructure, including VPN services and proxies, and used certificates with these subjects:

    • Certificate subject: CN=vpn,OU=users,O=global
    • Certificate subject: CN=vpn-user,OU=users,O=global
    • Certificate subject: CN=vpnuser,OU=users,O=global

    The list is not complete, and other subjects may be in use. Administrators should check logs for any unusual certificate-based Mobile Access login, not only those with these subjects. They should also check what suspicious Mobile Access users do after logging in, which often includes scanning internal ports and services.

    Check Point says customers who installed the September 9 fix are protected, but its advisory does not say whether any attempt succeeded.

    For gateways that cannot be patched yet, the NCSC lists a Check Point workaround for Site-to-Site VPN: turn off the implied VPN rules and allow UDP ports 500 and 4500 only from specific peer IP addresses. The workaround does not apply to locally managed Spark firewalls. Mitigation steps from Check Point are in sk1000117.

    attacks check Exploited management Point server targeted warns ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

    Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity

    BigCommerce Data Stolen via Ribon Apps Hack

    New ClosedQuorum Windows malware uses AI for attack decisions

    Reducing shadow IT visibility gaps with Wazuh

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Founder Summit’s agenda revealed | TechCrunch

    September 22, 2026

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    September 22, 2026

    UN Security Council Will Get Advice on AI Risks From Tech Giants Building It

    September 22, 2026

    Renewables: Grid shortages are forcing India to produce and waste green energy

    September 22, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Founder Summit’s agenda revealed | TechCrunch

    September 22, 2026

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    September 22, 2026

    UN Security Council Will Get Advice on AI Risks From Tech Giants Building It

    September 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.