Check Point Patches Exploited Management Server Zero-Day
Check Point has issued urgent fixes for CVE-2026-93616, a CVSS 9.8 directory traversal and file upload flaw exploited in attacks against Management Server. The issue affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent, allowing unauthenticated attackers to upload and run arbitrary scripts. The company also reports exploitation attempts targeting Spark Firewall customers through CVE-2026-85102, which can bypass VPN authentication and enable code execution on Security Gateway and Spark Firewall; organizations should apply the available updates and restrict Management Server access to trusted IP addresses.