AI blog

Check Point Confirms Active Exploitation of a Critical Security Management Zero-Day

AI Security · Part 1

A security product is supposed to reduce an organization's attack surface.

That makes vulnerabilities in the security platform itself particularly important.

On September 22, Check Point published an emergency security advisory covering two actively exploited vulnerabilities affecting its enterprise security infrastructure.

The most important is CVE-2026-93616, a newly discovered pre-authentication vulnerability affecting Check Point Security Management.

Check Point assigns the vulnerability a CVSS score of 9.8 and says it has observed a small number of targeted attacks exploiting the issue. A security fix is now available.

The company also confirmed active exploitation of CVE-2026-85102, another CVSS 9.8 vulnerability affecting Security Gateway and Spark Firewall products. That vulnerability had already been patched on September 9, but Check Point says exploitation attempts began appearing shortly afterward.

The combination deserves immediate attention from defenders.

These are not theoretical vulnerabilities supported only by laboratory proof-of-concept code.

Check Point has observed real exploitation.

And one of the vulnerabilities targets the system responsible for centrally managing security policy across enterprise networks.

What CVE-2026-93616 Actually Does

CVE-2026-93616 affects Check Point's Security Management web service.

According to Check Point, the vulnerability is a pre-authentication path-traversal flaw.

That first property matters.

Pre-authentication means the attacker does not first need a valid administrator account.

The path-traversal condition can allow an attacker to execute a script from an arbitrary path and load an arbitrary Java class.

Conceptually, the security boundary looks something like:

Attacker ↓ Security Management web service ↓ Pre-authentication vulnerability ↓ Arbitrary-path script execution ↓ Java class loading ↓ Management server compromise

Check Point says the flaw affects multiple releases, including supported R82.20, R82.10, R82 and R81.20 versions as well as several end-of-support releases.

Importantly, the company notes that LivePatch Takes 28 and 29 do not fix CVE-2026-93616. Administrators need to follow the specific remediation guidance associated with the vulnerability.

Check Point says it observed a handful of targeted attacks involving the vulnerability on July 23, 2026.

The company has not publicly provided enough evidence to responsibly attribute those attacks to a specific threat actor.

That distinction should be maintained.

A second vulnerability is also being exploited

The same advisory contains another important development.

CVE-2026-85102 affects VPN certificate handling in Check Point Security Gateway and Spark Firewall products.

It is also rated CVSS 9.8.

In this case, improper validation of certificate data during VPN negotiation can allow unauthenticated remote code execution.

Check Point had already disclosed and patched this vulnerability on September 9.

At the time, the company said it had no evidence that attackers were exploiting it.

That situation changed.

Check Point says it began observing exploitation attempts against Spark customers on September 12.

The attacks originated through anonymization infrastructure such as VPN services and proxies.

Check Point also published several certificate subject strings it observed in attacks, while explicitly warning administrators not to treat those strings as an exhaustive indicator set.

This is an important incident-response detail.

Indicators of compromise are useful.

But defenders should not turn them into overly narrow detection rules.

If a security team searches only for one certificate string published by the vendor, an attacker can simply change the string.

The better approach is behavioral:

Unexpected certificate authentication + Suspicious Mobile Access login + Internal reconnaissance + Unusual follow-on activity

Check Point specifically recommends reviewing anomalous certificate-based Mobile Access logins and looking for subsequent behavior such as internal port and service scanning.

Verified facts versus analysis

Verified: Check Point has confirmed exploitation of CVE-2026-85102 and CVE-2026-93616, both have CVSS scores of 9.8, and fixes are available.

Verified: CVE-2026-93616 was observed in a small number of targeted attacks, while CVE-2026-85102 has been observed in a broader wave against Spark customers.

Analysis: Organizations that exposed affected management infrastructure should consider the possibility that patching alone may not be sufficient. If exploitation occurred before remediation, incident-response procedures may be appropriate.

Why Management-Plane Vulnerabilities Are Especially Dangerous

Not all servers have equal security importance.

Consider a normal application server.

If attackers compromise it, they may gain access to the application's data and whatever systems that server can reach.

A centralized security-management server is different.

Its purpose is to control the infrastructure protecting everything else.

Check Point Security Management is used to manage security policies, administrator changes and logging across enterprise security deployments. BleepingComputer describes it as the central repository for those functions.

That makes management-plane systems attractive targets.

A simplified enterprise architecture might look like:

             Security Management
                   ↓
   ┌───────────────┼───────────────┐
   ↓               ↓               ↓
Firewall        VPN Gateway      Security Logs
   ↓               ↓               ↓

Servers Employees SOC / SIEM

The management system sits above several security controls.

This creates the possibility of disproportionate impact when it is compromised.

An attacker reaching the management plane may potentially gain access to information useful for understanding network architecture, security policies and administrative activity.

The exact impact depends on the product configuration and what the attacker successfully accesses.

There is no evidence in Check Point's advisory that every exploitation attempt resulted in full enterprise compromise.

But the architectural risk is enough to justify urgent response.

This is why management interfaces should rarely face the internet

One of the most basic defensive controls is also one of the most valuable:

do not expose management interfaces broadly when they do not need to be exposed.

Check Point has repeatedly recommended restricting management access through Trusted Clients.

That principle applies far beyond Check Point.

Firewalls, hypervisors, backup servers, VPN concentrators, identity systems, Kubernetes management interfaces and cloud administration consoles all deserve stricter exposure rules than ordinary services.

Ideally:

Internet ✕ Management interface

Admin workstation ↓ Trusted network / VPN / bastion ↓ Management interface

Reducing network reachability does not replace patching.

But it removes opportunities for attackers to reach vulnerable code in the first place.

Defense in depth matters precisely because security software itself can contain vulnerabilities.

What Security Teams Should Do Now

The first action is straightforward:

identify affected Check Point infrastructure and install the appropriate fixes.

Check Point's advisory links to separate support articles containing the exact affected releases, hotfix takes, validation commands and upgrade instructions.

But because exploitation is confirmed, the response should not stop with patch deployment.

Organizations should also determine whether vulnerable systems were exposed during the exploitation window.

That means answering questions such as:

Was the management service reachable from untrusted networks? Was Mobile Access enabled? Were affected Spark devices exposed? When was the relevant hotfix installed? Do logs exist for the period before remediation? Were unusual administrator or VPN sessions observed? Did suspicious sessions perform internal reconnaissance?

For CVE-2026-85102 specifically, Check Point recommends reviewing Mobile Access logs for anomalous certificate-based authentication.

Security teams should also investigate follow-on activity.

An attacker who successfully compromises a security gateway may not remain on that device.

The gateway can become an entry point.

Conceptually:

External exploitation ↓ Security appliance ↓ Internal reconnaissance ↓ Credential discovery ↓ Lateral movement ↓ Persistent access

This is why incident response distinguishes between remediation and eradication.

Installing a patch remediates the vulnerability.

It does not automatically eradicate an attacker who already moved elsewhere.

Review administrative credentials

Credential review is also appropriate when a management system may have been compromised.

Security teams should evaluate whether privileged credentials accessible to or used through affected systems require rotation.

That does not mean every Check Point customer must automatically rotate every enterprise password.

Response should remain evidence-driven.

But credentials associated with confirmed or strongly suspected compromised systems deserve additional scrutiny.

Preserve evidence before destroying it

There is another operational consideration.

Teams under pressure often patch or rebuild a vulnerable server immediately.

That may be correct when exploitation is ongoing.

But rebuilding can also destroy useful forensic evidence.

Where operationally feasible, incident-response teams should preserve relevant logs, system state and security telemetry before making destructive changes.

That information may help determine:

Was the vulnerability exploited? ↓ What executed? ↓ Which account was used? ↓ Where did the attacker connect? ↓ What happened next?

That sequence is often more valuable than knowing merely that the server was vulnerable.

Takeaway

The Check Point advisory is today's highest-priority security development because two critical vulnerabilities are confirmed to be exploited in real attacks.

CVE-2026-85102 provides a pre-authentication remote-code-execution path through VPN certificate processing, while CVE-2026-93616 affects the Security Management web service and can lead to arbitrary-path script execution and Java class loading.

Fixes exist for both.

Security teams should therefore prioritize:

inventory → exposure assessment → patching → verification → threat hunting → incident response where evidence warrants it.

The broader lesson extends beyond Check Point.

Firewalls, VPNs, identity platforms and security-management servers are themselves software.

They contain vulnerabilities.

And because they often occupy highly trusted positions inside enterprise networks, compromising the system responsible for enforcing security can sometimes be more valuable to an attacker than compromising an ordinary application server.

That is why the management plane deserves some of the strongest isolation, monitoring and patch discipline in the enterprise.