Tech News
← Home  ·  All topics

Check Point

4 GoKawiil briefs on this topic

Check Point confirms active exploitation of two VPN gateway flaws

Check Point disclosed that hackers are actively exploiting CVE-2026-85102, a pre-authentication remote code execution flaw in its Security Gateway VPN certificate handling, and CVE-2026-93616, a path traversal bug in its Management web service. The company says the path traversal flaw has been exploited as a zero-day since July 23, while exploitation of the gateway flaw began September 12 using VPNs and proxies to mask attacker origin. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 25, 2026 to patch.

Check Point patches actively exploited zero-day in Security Management Server

Check Point Software has issued emergency hotfixes for CVE-2026-93616, a critical path traversal vulnerability in its Security Management Server that lets unauthenticated attackers upload and run arbitrary scripts. The company confirmed the flaw is being actively exploited, with a handful of customers already compromised, and released a fix in R82.20 Security Hotfix covering Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.

Check Point patches critical root RCE bug in Security Management Server, Log Server

Check Point has issued security updates for CVE-2026-91843, a stack-based buffer overflow in the login process of its Security Management Server and Log Server products. The flaw allows unauthenticated attackers to remotely execute code with root privileges in low-complexity attacks requiring no user interaction. Check Point says it isn't aware of active exploitation but has provided detection guidance and interim mitigations for customers who can't immediately apply the fix.

Dutch NCSC warns Check Point VPN flaws face imminent exploitation

The Dutch NCSC has issued an alert about two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, warning that attacks exploiting them are likely to begin soon even though no public proof-of-concept exploit exists yet. Check Point released patches for both bugs on September 9, covering Security Gateways and Management Servers across multiple supported and end-of-support versions.