AI Weekly Malaysia

Back to items Summaries

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

ID
27436
Status
summarized
Published
23 Sep 2026, 2:29 AM
Fetched
23 Sep 2026, 5:09 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/check-point-warns-of-management-server.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.0
Created
23 Sep 2026, 5:10 AM
Tags
Audience
developerssaas_founders

What happened

Check Point disclosed a CVSS 9.8 path traversal zero-day (CVE-2026-93616) in its Security Management Server web service, exploited in targeted attacks on July 23 before a fix shipped September 22. The flaw lets unauthenticated attackers upload and execute scripts on the server that controls firewall policies. Check Point also reported active exploitation attempts since September 12 against a VPN flaw (CVE-2026-85102) fixed September 9, targeting Spark small-business firewall customers.

Why it matters

If your organization runs Check Point Security Management Server on R82.20, R82.10 (Jumbo Hotfix Take 44 or below), R82 (Take 126 or below), or R81.20 (Take 166 or below), patch now—this is an unauthenticated remote code execution on the box that governs your firewall rules. The September 16 LivePatch (Take 28/29) does NOT fix this CVE; you need the September 22 update specifically.

Discussion angle

How many of us actually know which firewall management stack our infra runs on, and whether a CVSS 9.8 RCE on that management plane would let an attacker rewrite our firewall rules silently—a problem that's worse than compromising any single server.

Top