Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Reported exploitedCheck Point Security Management ServerCheck Point Spark FirewallsOur summary
Check Point says CVE-2026-93616 was used in targeted attacks against its Security Management Server on July 23. The path traversal vulnerability can let an unauthenticated attacker upload and execute scripts through the server's web service, so administrators should apply the fixes in sk1000171 and investigate for prior compromise. The company also reported exploitation attempts against CVE-2026-85102 on Check Point Spark Firewalls, a VPN certificate-validation flaw fixed on September 9.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.