{"id":182,"date":"2026-09-25T00:43:40","date_gmt":"2026-09-25T00:43:40","guid":{"rendered":"https:\/\/managedt.com\/blog\/check-point-management-server-zero-day-targeted-attacks\/"},"modified":"2026-09-25T00:43:41","modified_gmt":"2026-09-25T00:43:41","slug":"check-point-management-server-zero-day-targeted-attacks","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/check-point-management-server-zero-day-targeted-attacks\/","title":{"rendered":"Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks"},"content":{"rendered":"<p>Check Point administrators can now close a critical management server path traversal flaw that attackers exploited in a handful of targeted attacks on July 23. The company released a fix on September 22 for CVE-2026-93616, a zero-day vulnerability in the Security Management Server that carries a 9.8 CVSS score. A second alert covers active attempts, beginning September 12, to exploit a VPN certificate flaw that Check Point fixed on September 9.<\/p>\n<h2>What Makes CVE-2026-93616 So Dangerous<\/h2>\n<p>CVE-2026-93616 is a path traversal bug in the management server&#8217;s web service. The service does not properly limit which files and folders a request can reach. An attacker who can access the web service can exploit the flaw to upload scripts to the server and then run them, without logging in. Check Point rated the vulnerability 9.8 out of 10 on the CVSS scale in the CVE record.<\/p>\n<p>The management server controls firewall policies for the Check Point gateways it manages. Check Point&#8217;s advisory does not name the targets of the July attacks or the attackers, nor does it say what the attackers did after exploiting the flaw. It also does not state what network access an attacker needs.<\/p>\n<h2>Which Management Server Versions Are Affected<\/h2>\n<p>Check Point numbers the Jumbo Hotfix updates for each release by Take. The CVE record lists these versions as affected:<\/p>\n<ul>\n<li>R82.20 with no Jumbo Hotfix installed<\/li>\n<li>R82.10 with Jumbo Hotfix Take 44 or below<\/li>\n<li>R82 with Jumbo Hotfix Take 126 or below<\/li>\n<li>R81.20 with Jumbo Hotfix Take 166 or below<\/li>\n<li>R81.10 with Jumbo Hotfix Take 190 or below (end of support)<\/li>\n<li>R81, R80.40, R80.30, R80.20, R80.10 and R80 (all end of support)<\/li>\n<\/ul>\n<p>Check Point&#8217;s advisory lists R82.20 as affected without the no Jumbo Hotfix condition. Administrators should note that the LivePatch fix for a separate management server flaw, CVE-2026-91843, released on September 16 as LivePatch Take 28 or Take 29 on R82.20, does not fix CVE-2026-93616.<\/p>\n<p>One take number matters for anyone who patched the earlier VPN certificate flaw CVE-2026-85103. On R82.10, R82, and R81.20, the new flaw&#8217;s affected list goes one take higher than that flaw&#8217;s. A server updated only enough to be outside the September flaw&#8217;s range is still affected by CVE-2026-93616.<\/p>\n<h2>How to Apply the Fix and Check for Compromise<\/h2>\n<p>Fixed builds, mitigation guidance, hunting steps, and indicators of compromise are in Check Point support article sk1000171. Administrators should follow three steps:<\/p>\n<ol>\n<li>Check the server&#8217;s release and Jumbo Hotfix take against the affected list.<\/li>\n<li>Install the fix listed in sk1000171.<\/li>\n<li>Use the hunting guidance and indicators of compromise in sk1000171 to look for signs of an attack.<\/li>\n<\/ol>\n<p>Installing the fix does not show whether the server was attacked before. Running the hunting checks is the only way to establish that.<\/p>\n<h2>Spark Firewalls Targeted Through VPN Flaw<\/h2>\n<p>CVE-2026-85102 sits in the way Check Point gateways check certificates while a VPN connection is being set up. It may let an attacker who has not logged in run code on the gateway. Fixes have been available since September 9 and are documented in support article sk1000117.<\/p>\n<p>The affected products are Security Gateway and Spark firewalls, whether centrally or locally managed, on R81 and R81.10 (both end of support), R81.10.x, R81.20, R82, R82.00.x and R82.10. The Netherlands&#8217; National Cyber Security Centre states the flaw applies when these products use Site-to-Site VPN or Remote Access VPN.<\/p>\n<p>Check Point says attackers have been attempting exploitation since September 12, targeting customers of Spark, the company&#8217;s firewall line for small businesses. When the fix came out, Check Point had no evidence the flaw was being exploited. The attempts came from anonymizing infrastructure, including VPN services and proxies, and used certificates with these subjects:<\/p>\n<ul>\n<li>CN=vpn,OU=users,O=global<\/li>\n<li>CN=vpn-user,OU=users,O=global<\/li>\n<li>CN=vpnuser,OU=users,O=global<\/li>\n<\/ul>\n<p>The list is not complete, and other subjects may be in use. Administrators should check logs for any unusual certificate-based Mobile Access login, not only those with these subjects. They should also check what suspicious Mobile Access users do after logging in, which often includes scanning internal ports and services.<\/p>\n<p>Check Point says customers who installed the September 9 fix are protected, but the advisory does not say whether any attempt succeeded. For gateways that cannot be patched yet, the NCSC lists a Check Point workaround for Site-to-Site VPN: turn off the implied VPN rules and allow UDP ports 500 and 4500 only from specific peer IP addresses. The workaround does not apply to locally managed Spark firewalls.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is CVE-2026-93616 in Check Point?<\/h3>\n<p>CVE-2026-93616 is a path traversal vulnerability in the Security Management Server&#8217;s web service, rated 9.8 on the CVSS scale. It allows an attacker with access to the web service to upload and run scripts without logging in. Attackers exploited it in targeted attacks on July 23, 2026.<\/p>\n<h3>Which Check Point versions need the CVE-2026-93616 fix?<\/h3>\n<p>Affected versions include R82.20 with no Jumbo Hotfix, R82.10 with Jumbo Hotfix Take 44 or below, R82 with Take 126 or below, R81.20 with Take 166 or below, and R81.10 with Take 190 or below, plus older end-of-support releases R81 through R80.<\/p>\n<h3>How do I protect a Check Point Spark firewall from CVE-2026-85102?<\/h3>\n<p>Install the fix from Check Point support article sk1000117, released September 9. Customers who installed that fix are protected. For gateways that cannot be patched yet, a workaround for Site-to-Site VPN involves turning off implied VPN rules and allowing UDP ports 500 and 4500 only from specific peer IP addresses.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is CVE-2026-93616 in Check Point?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CVE-2026-93616 is a path traversal vulnerability in the Security Management Server's web service, rated 9.8 on the CVSS scale. It allows an attacker with access to the web service to upload and run scripts without logging in. Attackers exploited it in targeted attacks on July 23, 2026.\"}},{\"@type\":\"Question\",\"name\":\"Which Check Point versions need the CVE-2026-93616 fix?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Affected versions include R82.20 with no Jumbo Hotfix, R82.10 with Jumbo Hotfix Take 44 or below, R82 with Take 126 or below, R81.20 with Take 166 or below, and R81.10 with Take 190 or below, plus older end-of-support releases R81 through R80.\"}},{\"@type\":\"Question\",\"name\":\"How do I protect a Check Point Spark firewall from CVE-2026-85102?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Install the fix from Check Point support article sk1000117, released September 9. Customers who installed that fix are protected. For gateways that cannot be patched yet, a workaround for Site-to-Site VPN involves turning off implied VPN rules and allowing UDP ports 500 and 4500 only from specific peer IP addresses.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/thehackernews.com\/2026\/09\/check-point-warns-of-management-server.html\" target=\"_blank\" rel=\"nofollow noopener\">thehackernews.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Check Point patched a critical management server flaw rated 9.8 that attackers exploited in July, and warns of active VPN exploitation attempts against Spark<\/p>\n","protected":false},"author":3,"featured_media":181,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-182","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/182","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=182"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/182\/revisions"}],"predecessor-version":[{"id":183,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/182\/revisions\/183"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/181"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=182"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=182"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=182"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}