Zero Day Room
Live
Vulnerabilities

Check Point Zero-Day Exploited in Targeted July Attacks

Check Point has disclosed that a critical zero-day vulnerability in its Security Management Server was exploited in targeted attacks in July.

Check Point has disclosed that a critical zero-day vulnerability in its Security Management Server was exploited in...

Attackers exploited a previously unknown vulnerability in Check Point's Security Management Server in targeted attacks on July 23. The company released a fix for the critical flaw, tracked as CVE-2026-93616, on September 22.

The flaw is a path traversal bug in the management server's web service, which fails to properly restrict file and folder access. This allows an unauthenticated attacker who can reach the server's web service to upload and execute scripts. Check Point assigned the vulnerability a severity score of 9.8 out of 10 on the CVSS scale.

Check Point's advisory does not identify the targets of the July attacks or the attackers' motives. It also does not specify what actions the attackers took after gaining access.

Affected Versions and Fix Guidance

The vulnerability affects multiple versions of the Security Management Server software. Administrators must check their server's release and Jumbo Hotfix 'Take' number against the following list.

Affected VersionJumbo Hotfix Condition
R82.20With no Jumbo Hotfix installed
R82.10With Jumbo Hotfix Take 44 or below
R82With Jumbo Hotfix Take 126 or below
R81.20With Jumbo Hotfix Take 166 or below
R81.10With Jumbo Hotfix Take 190 or below (end of support)
R81, R80.40, R80.30, R80.20, R80.10, R80All end of support

Check Point states that a server updated only enough to be protected from a separate VPN certificate flaw fixed on September 9, CVE-2026-85103, may still be vulnerable to this new attack. The company's full guidance on fixed builds, mitigation, threat hunting, and indicators of compromise is available in its support article, sk1000171.

Separate VPN Flaw Under Active Attack

Separately, Check Point reports that attackers have been attempting to exploit a different vulnerability since September 12. This flaw, tracked as CVE-2026-85102, affects the VPN functionality in Check Point gateways and its Spark firewall line for small businesses. Check Point had released a fix for this issue on September 9, at which time it had no evidence of exploitation.

The vulnerability exists in how gateways validate certificates during VPN setup and could allow an unauthenticated attacker to execute code. According to the Netherlands' National Cyber Security Centre (NCSC), the flaw applies when products use Site-to-Site VPN or Remote Access VPN.

Check Point says the ongoing attempts originate from anonymizing infrastructure like VPN services and proxies. The attacks have used certificates with subjects including 'CN=vpn,OU=users,O=global' and 'CN=vpn-user,OU=users,O=global'. The company cautions that this list is not exhaustive.

Recommended Actions for Administrators

For the management server flaw, administrators must immediately verify their software version and apply the fix detailed in sk1000171. Installing the patch does not reveal whether a server was compromised prior to the update, so using the provided hunting guidance is critical.

Regarding the VPN flaw, customers who installed the September 9 patch are protected. For gateways that cannot be patched immediately, the NCSC lists a workaround for Site-to-Site VPN involving disabling implied VPN rules and restricting UDP ports 500 and 4500 to specific peer IP addresses. This workaround does not apply to locally managed Spark firewalls. Full mitigation steps are in Check Point's support article sk1000117.

Check Point advises administrators to scrutinize logs for any unusual certificate-based Mobile Access logins and to monitor the post-login activities of suspicious users, which often include internal network scanning.

Related coverage

More from Vulnerabilities