Executive Summary
On July 23, 2026, attackers exploited a previously unknown zero-day vulnerability (CVE-2026-93616) in Check Point's Security Management Server during targeted attacks. The critical path traversal flaw allowed unauthenticated attackers to upload and execute scripts on management servers that control firewall policies across Check Point gateway infrastructures. Check Point released patches on September 22, 2026, rating the vulnerability 9.8/10 on the CVSS scale. Separately, since September 12, attackers have been actively exploiting a VPN certificate validation flaw (CVE-2026-85102) targeting Check Point Spark firewalls for small businesses.
This incident highlights the growing sophistication of attacks targeting critical network infrastructure management systems. As organizations increasingly rely on centralized security management platforms, vulnerabilities in these systems create single points of failure that can compromise entire network security postures, making immediate patching and infrastructure hardening essential priorities.
Why This Matters Now
Zero-day attacks on network security management infrastructure are escalating, with attackers specifically targeting the control planes that govern enterprise firewall policies. This represents a shift toward compromising the foundational systems that secure entire network perimeters.
Attack Path Analysis
Attackers exploited CVE-2026-93616, a path traversal vulnerability in Check Point Security Management Server web service, to upload and execute malicious scripts without authentication. Following initial compromise of the management infrastructure, attackers likely escalated privileges within the management plane, moved laterally across managed security devices, established command and control through the compromised management server, exfiltrated security policies and network topology data, and potentially impacted security posture by manipulating firewall rules.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-93616 path traversal vulnerability in Check Point Security Management Server web service to upload malicious scripts without authentication
Related CVEs
CVE-2026-93616
CVSS 9.8A path traversal vulnerability in Check Point Security Management Server web service allows unauthenticated remote attackers to upload and execute arbitrary scripts via improper file/folder request limitations.
Affected Products:
Check Point Security Management Server – R82.20 (no Jumbo Hotfix), R82.10 (Take 44 or below), R82 (Take 126 or below), R81.20 (Take 166 or below), R81.10 (Take 190 or below), R81, R80.x (all versions)
Exploit Status:
exploited in the wildCVE-2026-85102
CVSS 9.8A vulnerability in Check Point gateway certificate validation during VPN connection setup allows unauthenticated remote attackers to potentially execute code on the gateway.
Affected Products:
Check Point Security Gateway – R81, R81.10, R81.10.x, R81.20, R82, R82.00.x, R82.10
Check Point Spark Firewalls – R81, R81.10, R81.10.x, R81.20, R82, R82.00.x, R82.10
Exploit Status:
active scanning observed
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Process Injection
Valid Accounts: Local Accounts
File and Directory Discovery
Server Software Component: Web Shell
Masquerading
Exploitation of Remote Services
Automated Exfiltration
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Vulnerability Management Testing
Control ID: 11.3.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.08
DORA – Identification and Protection
Control ID: Article 8
CISA ZTMM 2.0 – Encrypted Network Traffic
Control ID: Network Environment
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
Check Point management server zero-day exploitation directly impacts cybersecurity infrastructure, requiring immediate patching of network security management systems and VPN gateways.
Financial Services
Banking institutions face critical risk from compromised firewall management and VPN vulnerabilities, threatening transaction security and regulatory compliance frameworks.
Health Care / Life Sciences
Healthcare networks using Check Point security infrastructure vulnerable to lateral movement attacks, risking patient data protection and HIPAA compliance violations.
Government Administration
Government agencies with Check Point deployments face targeted attacks exploiting management server vulnerabilities, compromising critical infrastructure and sensitive data systems.
Sources
- Check Point Warns of Management Server Zero-Day Exploited in Targeted Attackshttps://thehackernews.com/2026/09/check-point-warns-of-management-server.htmlVerified
- Security Advisory: Action Required - Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/Verified
- NCSC Advisory on Check Point VPN Vulnerability CVE-2026-85102https://advisories.ncsc.nl/2026/ncsc-2026-0365.htmlVerified
- Check Point Support Article SK1000171https://support.checkpoint.com/results/sk/sk1000171Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this Check Point management server compromise by limiting lateral movement through segmentation and reducing the blast radius of the security infrastructure breach.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial vulnerability exploitation would likely have occurred, but the scope of management server access could have been constrained through workload isolation and network-level segmentation controls
Control: Zero Trust Segmentation
Mitigation: Administrative privilege scope would likely have been reduced through identity-aware access controls and segmented administrative planes limiting cross-system privilege inheritance
Control: East-West Traffic Security
Mitigation: Lateral movement to managed security devices would likely have been significantly constrained through east-west traffic inspection and microsegmentation between management and operational network segments
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely have been detected and constrained through comprehensive traffic analysis and anomaly detection across the management infrastructure
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration scope would likely have been reduced through controlled egress policies and outbound traffic inspection limiting the volume and types of security data that could be extracted
While some policy manipulation risk would likely remain, the overall impact scope would have been significantly reduced due to segmented access controls and limited lateral movement capabilities
Impact at a Glance
Affected Business Functions
- Network Security Management
- Firewall Policy Administration
- VPN Access Control
- Network Infrastructure Protection
Estimated downtime: 3 days
Estimated loss: N/A
Potential exposure of network infrastructure configurations, firewall policies, VPN certificates, and administrative credentials for Security Management Server environments
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate management infrastructure and prevent lateral movement from compromised security devices
- • Deploy Multicloud Visibility & Control to detect anomalous management plane activities and suspicious automation patterns
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration from management servers to external destinations
- • Utilize Threat Detection & Anomaly Response capabilities to baseline normal management server behavior and alert on deviations
- • Apply Cloud Native Security Fabric inline enforcement to inspect and control traffic between management servers and managed devices



