**Critical Unauthenticated Flaws Target Check Point Security Management and VPN Gateways**
Cybersecurity analysts have uncovered two significant vulnerabilities in Check Point security infrastructure that have been the subject of recent cyberattacks. One flaw was exploited in targeted intrusions against management servers last summer, while the other continues to see active attack attempts against small business firewall appliances. Both vulnerabilities allow unauthenticated attackers to execute malicious code, posing severe risks to enterprise network security.
**Management Server Path Traversal Vulnerability**
A critical path traversal bug, cataloged as CVE-2026-93616, was leveraged in a series of targeted attacks on July 23. The vulnerability resides in the Security Management Server’s web service, which fails to properly restrict file and directory access for incoming requests. Because of this oversight, an attacker who can reach the web service can upload malicious scripts to the server and execute them remotely without ever providing login credentials. The flaw carries a severe severity score of 9.8 out of 10.
The vendor released a permanent fix for the management server on September 22. However, the specific identities of the targets, the origin of the July attackers, and the ultimate objectives of the exploitation campaign remain undisclosed. Several legacy software releases are affected, including R82.20 without the latest hotfix, R82.10 up to Take 44, R82 up to Take 126, and R81.20 up to Take 166. Older end-of-support iterations such as R81.10, R81, and the entire R80.x series are also susceptible.
It is crucial to note that an emergency update deployed on September 16 addressed a separate management server flaw and does not resolve CVE-2026-93616. Security teams must apply the specific hotfix designated for this path traversal bug.
**VPN Certificate Flaw Targeting Small Business Firewalls**
In a separate but related development, Check Point firewalls are facing persistent attack attempts focusing on a VPN certificate validation weakness, identified as CVE-2026-85102. Since September 12, threat actors have been bombarding customer gateways with exploitation attempts, specifically targeting the Spark firewall line, which is designed for small business environments. This vulnerability exists in how gateways validate certificates during VPN connection setup, potentially allowing an unauthorized attacker to run code on the gateway.
The attackers have been routing their attempts through anonymizing infrastructure, such as VPN services and proxies, and have used certificates with generic subjects like “CN=vpn” and “CN=vpn-user” to mask their identities. The vendor patched this VPN flaw on September 9, and customers who have applied this update are protected. For gateways running Site-to-Site VPN that cannot be patched immediately, a temporary workaround involves turning off implied VPN rules and restricting UDP traffic on ports 500 and 4500 to only trusted peer IP addresses. Additionally, administrators are advised to audit logs for any unusual certificate-based mobile access logins and monitor for subsequent internal network scanning by those users.
**Actionable Steps for Administrators**
Organizations running Check Point management servers and gateways should immediately verify their software versions against the affected lists and install the appropriate Jumbo Hotfix updates. After patching, teams should utilize threat hunting guidance and indicators of compromise to investigate whether the systems were breached prior to the fix, as installing the patch does not retroactively reveal past intrusions.
**Frequently Asked Questions (FAQ)**
**Q: What type of attack exploits CVE-2026-93616?**
A: It is a path traversal vulnerability that enables unauthenticated remote code execution. Attackers can bypass the login screen to upload and run malicious scripts directly on the management server.
**Q: Which specific Check Point products are vulnerable?**
A: The management server vulnerability affects various versions of the Security Management Server, while the VPN flaw impacts both Security Gateways and Spark firewalls across multiple supported software releases.
**Q: If I applied the September updates, am I fully protected?**
A: Not necessarily. A separate LivePatch update from September 16 addressed a different vulnerability and does not fix CVE-2026-93616. Administrators must verify their specific Jumbo Hotfix levels to ensure they have the correct patch for the path traversal flaw.
**Q: How can I detect if my system has been compromised?**
A: Security teams should review logs for anomalous Mobile Access login attempts using unusual certificate subjects and check for signs of internal network reconnaissance, such as unexpected port scanning originating from newly authenticated devices.
**Conclusion**
The active exploitation of these two critical vulnerabilities underscores the persistent threats facing network management infrastructure and gateway defenses. Immediate action is required for all organizations utilizing Check Point Security Management Servers and Spark firewalls to apply the latest patches, enforce temporary mitigations where necessary, and conduct thorough threat hunting. Delaying these updates leaves networks dangerously exposed to unauthorized remote access and potential data breaches.
Thank you for reading



