importantSYS.SOURCE: The Hacker News• 2026-09-22T23:59:39+05:30
Check Point Discloses Zero-Day Vulnerability in Management Server Exploited in Targeted Attacks
Check Point disclosed a zero-day vulnerability (CVE-2026-93616) in its Management Server allowing unauthenticated code execution through path traversal, with active exploitation in targeted attacks. A separate VPN flaw (CVE-2026-85102) affected Spark firewalls, prompting mitigation guidance for impacted systems.
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said.
The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point
*** END OF TRANSMISSION ***