CISA Warns of Multiple Check Point Product Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


The U.S. Cybersecurity and Infrastructure Security Agency has added two Check Point vulnerabilities to its Known Exploited Vulnerabilities Catalog, warning that attackers are actively exploiting the flaws against affected environments.

The issues affect Check Point Security Gateway, Spark Firewall, Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products.

The first flaw, CVE-2026-85102, is an improper certificate validation vulnerability (CWE-295) affecting Check Point Security Gateway and Spark Firewall deployments using Site-to-Site or Remote Access VPN.

An unauthenticated remote attacker could exploit the flaw to execute arbitrary code on a vulnerable gateway. This means an attacker may be able to run commands or deploy malicious payloads without first obtaining valid user credentials, creating a serious risk for organizations that expose affected VPN services to the internet.

The second issue, CVE-2026-93616, is a path traversal vulnerability affecting multiple Check Point management and logging products. It impacts Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.

The weakness is categorized as CWE-22, a flaw type that can let attackers access files or directories outside an intended restricted location.

Check Point Product Vulnerabilities Exploited

According to the advisory details, an unauthenticated attacker can abuse the vulnerability to upload and execute arbitrary scripts. Successful exploitation could give an attacker a foothold in a security-management environment, potentially enabling further network discovery, credential theft, policy manipulation, or malware deployment.

CISA added both vulnerabilities to its KEV Catalog on September 22, 2026, with a September 25 remediation deadline, urging organizations to follow Check Point’s mitigations, assess internet exposure, conduct forensic triage, and discontinue affected products if mitigations are unavailable.

Security teams should prioritize identifying vulnerable Check Point appliances and management servers, especially those reachable from the public internet. Administrators should review authentication records, VPN activity, system logs, uploaded files, and unusual script execution for signs of exploitation before and after remediation.

CISA’s advisory does not identify ransomware use for either vulnerability, listing that status as unknown. However, the ability to execute code or scripts without authentication makes both flaws high-priority risks for organizations using affected Check Point products.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post CISA Warns of Multiple Check Point Product Vulnerabilities Exploited in Attacks appeared first on Cyber Security News.