INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Check Point Management Server Zero-Day Exploited by Hackers

| 2026-09-23 06:14 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The US cybersecurity agency CISA has added two critical-severity vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a zero-day bug in Check Point's Security Gateway and Spark Firewall products. The first vulnerability, CVE-2026-85102, is described as an improper validation of certificate data during VPN negotiation, allowing remote attackers to bypass authentication and execute arbitrary code on the Security Gateway. This vulnerability has been patched by Check Point since September 9. A second vulnerability, CVE-2026-93616, is a directory traversal and file upload issue that could allow unauthenticated attackers to upload and execute arbitrary scripts on the Management Server. Check Point released urgent patches for this vulnerability as well. These vulnerabilities highlight the importance of timely patching and proper security measures in preventing exploitation by malicious actors.
Technical Mitigations AI-generated
• Limit access to the Management Server behind a security gateway or a firewall. • Limit access to port TCP/19009 to trusted IP addresses. • Apply the R82.20 Security Hotfix (TAR) and include fixes in Jumbo Hotfix Accumulator for affected versions.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SparkSparkQilinQilin CVE-2024-24919CVE-2024-24919 CVE-2026-18574CVE-2026-18574 CVE-2026-85102CVE-2026-85102 CVE-2026-91843CVE-2026-91843 CVE-2026-62144CVE-2026-62144 CVE-2026-85103CVE-2026-85103 CVE-2026-50751CVE-2026-50751 CVE-2026-93616CVE-2026-93616 CVE-2026-16232CVE-2026-16232
Target & Sectors
Global Scope technologytechnology
Incident Timeline
‎at least 2007
The FBI and CISA have urged software companies to remove path traversal weaknesses from their products since at least 2007.
attribution FBI
‎May 2024
The FBI and CISA urged software companies to remove path traversal weaknesses from their products since May 2024.
attribution FBI
‎July 22
An attacker exploited the CVE-2026-91843 vulnerability in Check Point's Security Management Server without logging in, starting on July 22.
tactic T1584.004 - Server
organisation The Security Management
vulnerability CVE-2026-91843
‎August 3
Threat actors exploited CVE-2026-18574, an authentication bypass vulnerability in Check Point's management server, on August 3.
vulnerability CVE-2026-85103
organisation CVE-2026
vulnerability CVE-2026-18574
organisation Quantum Security Management
‎September 9
Threat actors exploited a zero-day authentication bypass (CVE-2026-18574) and a heap overflow in VPN certificate decoding (CVE-2026-85103) to target Check Point's Security Gateway, Spark Firewall, and Quantum Security Management products.
source_region United States
vulnerability CVE-2026-85102
vulnerability CVSS score of 9.8
attribution CISA
organisation Known Exploited
tactic T1588.006 - Vulnerabilities
organisation KEV
organisation Check Point’s Security Gateway
malware Spark
vulnerability CVE-2026-85103
organisation CVE-2026
vulnerability CVE-2026-18574
organisation Quantum Security Management
‎September 9, 2026
Threat actors exploited a zero-day vulnerability in Check Point's management server, which was disclosed and patched by the vendor on September 9, 2026.
‎2026/09/10
Threat actors exploited a zero-day vulnerability in Check Point's management server after the company pushed fixes for two VPN certificate flaws on September 10, 2026.
‎2026/09/11
Threat actors exploited the newly patched CVE-2026-85103 heap overflow vulnerability in Check Point management systems to gain access, leading to a subsequent zero-day Remote Code Execution (CVE-2026-91843) via SmartConsole.
vulnerability CVE-2026-85103
tactic T1592.002 - Software
vulnerability CVE-2026-91843
tactic Remote Code Execution
‎September 16, 2026
Check Point issued a notice on September 16, 2026, advising customers to apply the LivePatch fix described in advisory sk1000155 due to exploitation of its management server by unknown threat actors.
organisation Check Point
‎September 16
Threat actors exploited a zero-day vulnerability in Check Point's management server without publicly available proof-of-concept exploit.
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
‎September 17
Threat actors exploited a zero-day vulnerability in Check Point's management server, which was not yet listed as known exploited by CISA.
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
‎September 18, 2026
Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed.
organisation Security Management
vulnerability CVE-2026-91843
‎2026/09/23
Threat actors exploited a stack-based buffer overflow vulnerability in Check Point's Security Management Server instances, allowing them to execute code with root privileges.
organisation the Dutch National Cyber Security Centre
organisation NCSC-NL
organisation Check Point VPN
organisation CVE-2026
infrastructure Linux
organisation Chinese Hackers
victims 3 Organizations
organisation Check Point
organisation the Jumbo Hotfix Accumulator
organisation LivePatch
organisation Check Point Management Servers
organisation Check Point Patches Exploited Management
organisation Security Management
organisation Multi-Domain Security Management
organisation SmartEvent
organisation IP
organisation The Security Management
organisation Security Gateways
organisation the Security Management/Log
organisation the Security Internal Communication
infrastructure 3,836 hosts
organisation SmartConsole
organisation Trusted Clients
organisation R80
organisation R80.10
organisation R80.20
organisation R81
organisation Check Point's
organisation Microsoft
organisation Global Properties and Data Access Control
organisation Access Control
organisation The Hacker News
organisation the Trusted Clients
organisation NFL
organisation CHANEL
organisation Check Point Fixes Critical CVE-2026-91843
organisation SecurityAffairs
organisation CVSS
organisation New Check Point
organisation Censys
organisation R82 Jumbo Hotfix Take
organisation EoS
organisation Check Point Management
organisation Manage & Settings
organisation Permissions & Administrators
organisation Standalone
organisation NHS England Digital
organisation LivePatches
organisation the User Center
organisation Fifth Critical Management Flaw
organisation Lotem Finkelstein
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
victims
3
Organizations
Metrics
infrastructure
3,836
Hosts