Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks Swati KhandelwalSep 22, 2026Network Security / Vulnerability Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point gateways it manages. Separately, Check Point said attackers have been trying since September 12 to exploit a VPN flaw it fixed on September 9. The attempts, against a flaw tracked as CVE-2026-85102, have targeted customers of Spark, Check…
CVEs: CVE-2026-93616, CVE-2026-85102, CVE-2026-91843, CVE-2026-85103
Original source: thehackernews.com