Check Point Patches Exploited Management Server Zero-Day
Reported exploitedManagement ServerSecurity GatewayOur summary
Check Point has issued urgent fixes for CVE-2026-93616, a CVSS 9.8 directory traversal and file upload flaw exploited in attacks against Management Server. The issue affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent, allowing unauthenticated attackers to upload and run arbitrary scripts. The company also reports exploitation attempts targeting Spark Firewall customers through CVE-2026-85102, which can bypass VPN authentication and enable code execution on Security Gateway and Spark Firewall; organizations should apply the available updates and restrict Management Server access to trusted IP addresses.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.