Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
- ID
- 27436
- Status
- summarized
- Published
- 23 Sep 2026, 2:29 AM
- Fetched
- 23 Sep 2026, 5:09 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/check-point-warns-of-management-server.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.0
- Created
- 23 Sep 2026, 5:10 AM
- Tags
- Audience
- developerssaas_founders
What happened
Check Point disclosed a CVSS 9.8 path traversal zero-day (CVE-2026-93616) in its Security Management Server web service, exploited in targeted attacks on July 23 before a fix shipped September 22. The flaw lets unauthenticated attackers upload and execute scripts on the server that controls firewall policies. Check Point also reported active exploitation attempts since September 12 against a VPN flaw (CVE-2026-85102) fixed September 9, targeting Spark small-business firewall customers.
Why it matters
If your organization runs Check Point Security Management Server on R82.20, R82.10 (Jumbo Hotfix Take 44 or below), R82 (Take 126 or below), or R81.20 (Take 166 or below), patch now—this is an unauthenticated remote code execution on the box that governs your firewall rules. The September 16 LivePatch (Take 28/29) does NOT fix this CVE; you need the September 22 update specifically.
Discussion angle
How many of us actually know which firewall management stack our infra runs on, and whether a CVSS 9.8 RCE on that management plane would let an attacker rewrite our firewall rules silently—a problem that's worse than compromising any single server.