news.mlab.sh
Back to the feed
vulnerability

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

CriticalCVSS 9.8
Summary

Check Point has warned of a zero-day exploit targeting its Security Management Server, initially used in targeted attacks. Attackers exploited CVE-2026-93616, a path traversal vulnerability, to upload scripts and run them on the server. A separate VPN flaw, CVE-2026-85102, was also exploited, targeting Spark firewalls. While patches are available, Check Point doesn't confirm whether any attacks were successful, and administrators are urged to check server versions, install updates, and monitor for suspicious activity.

Check Point has issued a security advisory regarding a zero-day vulnerability affecting its Security Management Server. Attackers exploited a previously unknown flaw, CVE-2026-93616, allowing them to upload and execute scripts on the server without authentication. The vulnerability stems from a path traversal bug in the server's web service, which does not properly limit file and folder access.

Separately, Check Point reported that attackers have been attempting to exploit a VPN flaw, CVE-2026-85102, since September 12. This vulnerability occurs during VPN connection setup, potentially enabling an unauthenticated attacker to run code on the gateway. The fix for this vulnerability was released on September 9, but Check Point doesn't confirm whether any attacks were successful.

The Security Management Server is affected by CVE-2026-93616, and the affected versions include R82.20 (without Jumbo Hotfix), R82.10 with Jumbo Hotfix Take 44 or below, R81.20 with Jumbo Hotfix Take 166 or below, R81.10 with Jumbo Hotfix Take 190 or below (end of support), R81, R80.40, R80.30, R80.20, R80.10 and R80 (all end of support). The VPN flaw, CVE-2026-85102, affects Security Gateway and Spark firewalls, whether centrally or locally managed, on R81 and R81.10 (both end of support), R81.10.x, R81.20, R82, R82.00.x and R82.10. The Netherlands' National Cyber Security Centre (NCSC) advises that this flaw applies when these products use Site-to-Site VPN or Remote Access VPN.

Check Point indicated that the attacks originated from anonymizing infrastructure, including VPN services and proxies, utilizing certificates with subjects such as CN=vpn,OU=users,O=global, and CN=vpn-user,OU=users,O=global. Administrators are urged to check logs for any unusual certificate-based Mobile Access login attempts, particularly those involving scanning internal ports and services. For gateways unable to be patched, the NCSC recommends disabling implied VPN rules and allowing UDP ports 500 and 4500 only from specific peer IP addresses – a workaround not applicable to locally managed Spark firewalls. Mitigation steps and indicators of compromise are detailed in support article sk1000171 and sk1000117.

Read the full article at The Hacker News