Check Point Warns of Active Exploitation of Critical Security Management Server Flaw

Attackers exploited a previously unknown vulnerability in Check Point's Security Management Server in a small number of targeted attacks on July 23, according to Check Point.

The vulnerability, tracked as CVE-2026-93616, is a critical path traversal flaw that can allow an attacker with access to the server's web service to execute scripts without authentication.

Check Point released a security fix for the vulnerability on September 22. Security Management Server is used to centrally manage firewall policies for Check Point security gateways.

The company also disclosed that attackers have been attempting to exploit a separate VPN vulnerability since September 12. That flaw, tracked as CVE-2026-85102, was patched by Check Point on September 9.

The attacks involving CVE-2026-85102 have targeted customers using Check Point's Spark firewall products for small businesses. When the September 9 patch was released, Check Point said it had no evidence that the vulnerability was being exploited.

Critical Security Management Server Vulnerability

CVE-2026-93616 affects the web service of Check Point Security Management Server.

The vulnerability is caused by improper restrictions on the files and directories that can be accessed through requests.

An attacker can exploit the flaw to upload scripts to the server and execute them without first authenticating.

Check Point has assigned the vulnerability a CVSS score of 9.8 out of 10, placing it in the critical severity category.

The company has not publicly identified the organizations targeted during the July attacks or disclosed the identity of the attackers.

Check Point has also not provided details about what attackers did after successfully exploiting the vulnerability.

Affected Security Management Server Versions

The affected versions listed in the CVE record include:

  • R82.20 with no Jumbo Hotfix installed
  • R82.10 with Jumbo Hotfix Take 44 or earlier
  • R82 with Jumbo Hotfix Take 126 or earlier
  • R81.20 with Jumbo Hotfix Take 166 or earlier
  • R81.10 with Jumbo Hotfix Take 190 or earlier
  • R81, R80.40, R80.30, R80.20, R80.10 and R80, which have reached end of support

Check Point's advisory lists R82.20 as affected without specifying the no-Jumbo-Hotfix condition.

Administrators should verify the installed Security Management Server version and Jumbo Hotfix level before determining whether their systems are affected.

Separate Management Server Vulnerability

Check Point also recently addressed another Security Management Server vulnerability, tracked as CVE-2026-91843, through its LivePatch mechanism on September 16.

The LivePatch update was listed as Take 28, or Take 29 for R82.20, according to France's CERT Santé.

However, Check Point confirmed that these LivePatch updates do not address CVE-2026-93616.

Administrators should therefore ensure that the specific fix for CVE-2026-93616 has been installed.

A separate vulnerability, CVE-2026-85103, affects VPN certificate handling and was patched on September 9. On several affected releases, the version ranges for CVE-2026-93616 extend beyond those affected by CVE-2026-85103.

This means that applying only the earlier VPN-related update may not protect a Security Management Server against CVE-2026-93616.

Check Point recommends administrators take the following steps:

  1. Check the Security Management Server release and Jumbo Hotfix Take against the affected versions.
  2. Install the security fix specified in Check Point support article sk1000171.
  3. Review the hunting guidance and indicators of compromise provided by Check Point.
  4. Investigate the server for signs of previous exploitation because installing the patch alone does not determine whether an attack occurred.

Check Point's advisory currently identifies Security Management Server as affected and does not publicly specify additional affected products.

Attackers Target Check Point Spark Firewalls

The second vulnerability, CVE-2026-85102, affects the way Check Point gateways validate certificates during VPN connection establishment.

The vulnerability can potentially allow an unauthenticated attacker to execute code on an affected gateway.

Check Point released fixes for CVE-2026-85102 on September 9.

Affected products include Security Gateway and Spark firewalls running various versions of R81, R81.10, R81.10.x, R81.20, R82, R82.00.x and R82.10.

According to the Netherlands National Cyber Security Centre, the vulnerability applies when the affected products use Site-to-Site VPN or Remote Access VPN.

Check Point said exploitation attempts originated from anonymizing infrastructure, including VPN services and proxies.

The attackers were observed using certificates with subjects including:

  • CN=vpn,OU=users,O=global
  • CN=vpn-user,OU=users,O=global
  • CN=vpnuser,OU=users,O=global

Check Point noted that the list may not be complete and that attackers could use other certificate subjects.

Administrators should therefore review logs for unusual certificate-based Mobile Access logins rather than relying only on the certificate names listed above.

They should also investigate suspicious activity following Mobile Access authentication, including attempts to scan internal ports and services.

Check Point says customers that installed the September 9 security update are protected, although the company has not disclosed whether any of the observed exploitation attempts were successful.

Mitigation for Systems That Cannot Be Patched

For gateways that cannot immediately be updated, the Netherlands National Cyber Security Centre has documented a mitigation for Site-to-Site VPN.

The workaround involves disabling implied VPN rules and restricting UDP ports 500 and 4500 to specific trusted peer IP addresses.

This mitigation does not apply to locally managed Spark firewalls.

Administrators should prioritize applying the official Check Point security updates and use the vendor's mitigation and threat-hunting guidance where immediate patching is not possible.

The disclosure highlights the importance of promptly patching internet-facing security management infrastructure, particularly when a vulnerability has already been exploited in targeted attacks.