NewsTradingSentimentEventsCommunityBriefing
Tech

Check Point Patches Zero-Day Exploited in July

By Tech Desk · · 2 min read
A server rack with blinking status lights in a dark room

Attackers used a management server flaw for targeted intrusions before the patch arrived.

Key points

  • Check Point patched a zero-day exploited in July targeted attacks on September 22.
  • The flaw allows unauthenticated script execution on the Security Management Server.
  • A separate VPN vulnerability in Spark firewalls is also under active exploitation attempts.

Check Point has released a fix for a critical zero-day vulnerability that was actively exploited in targeted attacks last month. The flaw allowed attackers to execute scripts on the Security Management Server without logging in, a risk the company rated near the maximum on the standard severity scale.

According to The Hacker News, the exploitation attempts occurred on July 23, yet the patch did not arrive until September 22. This two-month gap between attack and remedy leaves organizations that missed the initial warning exposed to potential compromise, even after updating their systems.

The Gap Between Attack and Fix

The vulnerability, identified as CVE-2026-93616, is a path traversal bug in the server’s web service. It fails to properly restrict which files a request can reach, enabling an attacker to upload and run malicious scripts. Because the server controls firewall policies for connected gateways, a compromise here can cascade across the entire network.

Check Point’s advisory does not name the specific targets or the attackers, nor does it detail what the intruders did after gaining access. The primary catch for administrators is that installing the patch does not retroactively remove any malicious code that was already executed during the window of exposure.

Complex Patching Requirements Create Risk

Determining whether a system is safe is complicated by Check Point’s versioning system, which uses specific "Take" numbers for hotfixes. A server might be updated to fix a different vulnerability but still remain vulnerable to this zero-day. For example, some release lines require a higher Take number than others to be fully protected.

Administrators must carefully compare their server’s release and hotfix level against the official list in support article sk1000171. Simply applying the latest general update may not be sufficient if the specific Take number required for this fix has not been met. This creates a trade-off where manual verification is required to ensure security.

Separate VPN Flaw Targets Small Business

In a related development, Check Point reported attempts to exploit a separate VPN vulnerability, CVE-2026-85102, since September 12. This flaw affects Spark firewalls used by small businesses and could allow unauthenticated code execution. The company fixed this issue on September 9, but attackers began testing it shortly after the patch was released.

The attempts came from anonymizing infrastructure, including proxies and VPN services, using specific certificate subjects. While the two flaws are distinct, they highlight a pattern of targeted probing against Check Point’s infrastructure components. Organizations using these products must address both issues to close all known entry points.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories