EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 95/100

Check Point ha rivelato che un zero-day, CVE-2026-93616, è stato sfruttato in attacchi mirati il 23 luglio. L'errore permette agli attaccanti di eseguire script senza autenticazione. Una patch è stata rilasciata il 22 settembre. Allo stesso tempo, un altro bug, CVE-2026-85102, è stato sfruttato da attacchi mirati a dispositivi Spark. La patch per il secondo bug è disponibile dal 9 settembre.

Why it matters

Per le PMI italiane, la vulnerabilità CVE-2026-93616 rappresenta un rischio elevato per i server di gestione Check Point, potenzialmente esposti a attacchi senza autenticazione. La mancanza di patch potrebbe portare a compromissioni critiche, con conseguenze significative sulla sicurezza e sull'integrità dei dati.

Potential operational benefits

  • Riduzione della superficie esposta a attacchi non autenticati
  • Miglioramento della visibilità e del controllo sugli accessi
  • Minimizzazione del rischio di compromissione critica dei server di gestione
  • Aumento della capacità di rilevamento e risposta agli attacchi
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementFirewall NGFW / IPSMonitoraggio / SIEMSegmentazione di reteBackup & DR
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
22/09/2026 20:29
MITRE ATT&CK
T1190, T1059.001, T1486
CVE
CVE-2026-93616
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source