Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exploitation of Critical Check Point Management Server Zero-Day Flaw: A Comprehensive Analysis




A critical zero-day flaw has been discovered in Check Point's Security Management Server, allowing an attacker to run scripts on the server without logging in. The vulnerability, designated as CVE-2026-93616, has been identified as a significant threat to organizations that utilize Check Point's Security Management Server for their firewall policies. Check Point has released a fix for the server that controls firewall policies for Check Point gateways, but it is essential for administrators to apply the fix to mitigate the effects of this vulnerability.

  • Check Point has issued a critical alert regarding a previously unknown zero-day flaw in its Security Management Server.
  • The vulnerability, CVE-2026-93616, allows an attacker to run scripts on the server without logging in, compromising its security.
  • Check Point has rated the vulnerability at 9.8 out of 10 on the CVSS scale, indicating its high severity.
  • The exploitation of this zero-day flaw has been reported in targeted attacks, mainly on Spark customers.
  • Check Point has released a fix for the server that controls firewall policies for Check Point gateways.
  • Another vulnerability, CVE-2026-85102, affects VPN functionality in Check Point gateways.
  • Administrators are advised to apply the fix and check for signs of an attack to mitigate the effects of the vulnerability.



  • Check Point, a renowned cybersecurity firm, has issued a critical alert regarding the exploitation of a previously unknown zero-day flaw in its Security Management Server. The vulnerability, designated as CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in, thereby compromising the security of the server. This critical vulnerability has been identified as a significant threat to organizations that utilize Check Point's Security Management Server for their firewall policies.

    The flaw, discovered by Check Point, is a path traversal bug in the management server's web service, which does not properly limit which files and folders a request can reach. This allows an attacker to upload scripts to the server and then run them, thereby gaining unauthorized access to the server. Check Point has rated the vulnerability at 9.8 out of 10 on the CVSS scale, indicating its high severity.

    The exploitation of this zero-day flaw has been reported in a handful of targeted attacks, which took place on July 23. The attackers exploited the vulnerability to gain access to the server and then ran scripts on it without logging in. However, it is worth noting that Check Point has released a fix for the server that controls firewall policies for Check Point gateways, which is designed to mitigate the effects of this vulnerability.

    In addition to the management server flaw, Check Point has also identified another vulnerability, CVE-2026-85102, which affects the VPN (Virtual Private Network) functionality of its gateways. This vulnerability allows an attacker who has not logged in to run code on the gateway, thereby compromising the security of the VPN connection.

    The affected products that are impacted by these vulnerabilities are Check Point's Security Gateway and Spark firewalls, whether centrally or locally managed. The versions of Check Point's software that are affected by these vulnerabilities include R82.20, R82.10, R82, R81.20, R81.10, R81.10.x, R81.20, R82.00.x, and R82.10.

    Check Point has advised administrators to check the server's release and Jumbo Hotfix take against the list of affected versions and to install the fix listed in support article sk1000171. The fix should be applied to the server that controls firewall policies for Check Point gateways. Additionally, administrators should use the hunting guidance and indicators of compromise in sk1000171 to look for signs of an attack.

    The affected products that are impacted by these vulnerabilities include Check Point's Security Gateway and Spark firewalls, whether centrally or locally managed. The versions of Check Point's software that are affected by these vulnerabilities include R82.20, R82.10, R82, R81.20, R81.10, R81.10.x, R81.20, R82.00.x, and R82.10. The Netherlands' National Cyber Security Centre (NCSC) has also issued a warning about the vulnerability, advising administrators to turn off the implied VPN rules and allow UDP ports 500 and 4500 only from specific peer IP addresses.

    Check Point has released a separate fix for the management server, CVE-2026-91843, through LivePatch. However, this fix does not address the CVE-2026-93616 vulnerability. The attempts to exploit this vulnerability have targeted customers of Spark, Check Point's firewall line for small businesses.

    In conclusion, the exploitation of the critical Check Point management server zero-day flaw is a significant threat to organizations that utilize Check Point's Security Management Server for their firewall policies. The vulnerability allows an attacker who can access the server's web service to run scripts on it without logging in, thereby compromising the security of the server. It is essential for administrators to apply the fix listed in support article sk1000171 to the server that controls firewall policies for Check Point gateways.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Exploitation-of-Critical-Check-Point-Management-Server-Zero-Day-Flaw-A-Comprehensive-Analysis-ehn.shtml

  • https://thehackernews.com/2026/09/check-point-warns-of-management-server.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-93616

  • https://www.cvedetails.com/cve/CVE-2026-93616/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-85102

  • https://www.cvedetails.com/cve/CVE-2026-85102/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-91843

  • https://www.cvedetails.com/cve/CVE-2026-91843/


  • Published: Tue Sep 22 15:18:32 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us