Overview
- Check Point confirmed a critical management‑server bug, tracked as CVE-2026-93616, has been exploited in targeted attacks and released emergency hotfixes on September 22 to stop unauthenticated attackers from uploading and running scripts.
- The flaw affects Security Management Server, Multi‑Domain Management, Log Server and SmartEvent, and standard LivePatch updates do not fix CVE-2026-93616 so administrators must install the R82.20 Security Hotfix or the listed Jumbo Hotfix takes.
- A separate VPN certificate‑handling bug, CVE-2026-85102, has seen active probing since September 12 against Spark firewalls and can allow pre‑authentication remote code execution and authentication bypass on Security Gateway and Spark devices.
- CISA added both CVE-2026-93616 and CVE-2026-85102 to its Known Exploited Vulnerabilities catalog and directed federal agencies to apply fixes or mitigations on an accelerated timetable, increasing pressure on public and private operators to act quickly.
- Check Point published indicators of compromise and hunting guidance and urged customers that installing fixes does not prove or remove past compromise so teams must review logs, run forensics, and restrict Management Server access to trusted IPs if they cannot patch immediately.