Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
Reported exploitedCheck Point Management ServerCheck Point Spark FirewallsOur summary
Check Point has issued emergency fixes for CVE-2026-93616, a pre-authentication path traversal flaw affecting its Management Server products, after attacks dating to July 23, 2026. Exploitation attempts are also targeting Check Point Spark Firewalls through CVE-2026-85102, an authentication bypass and RCE vulnerability; organizations should patch, review Mobile Access activity, and limit Management Server access where fixes cannot be applied. CISA also added CVE-2026-93952 in Arista VeloCloud Orchestrator and CVE-2026-94127 in F5 Networks’ BIG-IP APM to its Known Exploited Vulnerabilities catalog, highlighting the need to check affected systems for compromise.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.