Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Swati KhandelwalSep 22, 2026Network Security / Vulnerability

Check Point has recently addressed a critical flaw in its Security Management Server that was exploited by attackers in targeted attacks. The flaw, identified as CVE-2026-93616, allowed unauthorized access to the server’s web service, enabling attackers to run scripts without authentication. Check Point released a fix for this vulnerability on September 22, safeguarding the server responsible for managing firewall policies for Check Point gateways.

Additionally, Check Point disclosed ongoing attempts by attackers to exploit a VPN flaw, CVE-2026-85102, which was patched on September 9. The attacks targeted customers of Spark, Check Point’s firewall line for small businesses. Despite no evidence of active exploitation before the fix, Check Point remains vigilant about potential threats.

The path traversal bug in the management server’s web service, CVE-2026-93616, received a severity rating of 9.8 out of 10 on the CVSS scale. This flaw could allow malicious actors to upload and execute scripts on the server, posing a significant security risk.

Administrators are advised to check their server’s version against the list of affected versions provided by Check Point and apply the necessary fix. Furthermore, they should follow the mitigation steps outlined in support article sk1000171 to prevent potential attacks and investigate any signs of compromise.

While Check Point’s advisory focuses on the Security Management Server, the company has not disclosed specific details about the targets of the attacks or the attackers’ motives. The security community continues to monitor the situation closely to protect against emerging threats.

Management Server Versions and Fix

Check Point users are urged to stay informed about the latest updates and security patches to safeguard their systems against potential vulnerabilities. By following best practices and implementing recommended security measures, organizations can enhance their overall cybersecurity posture and mitigate risks effectively.

For more information and detailed guidance on addressing security vulnerabilities in Check Point products, refer to the official support resources provided by Check Point.