CVE Tools
Back to feed
Exploited in the wild Check Point Management Server rce Check Point Spark Firewalls Check Point zero-day

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances

Help Net Security·By Zeljka Zorz··3 min read
CVE Tools coverage

Check Point has issued emergency fixes for CVE-2026-93616, a pre-authentication path traversal flaw affecting its Management Server products, after attacks dating to July 23, 2026. Exploitation attempts are also targeting Check Point Spark Firewalls through CVE-2026-85102, an authentication bypass and RCE vulnerability; organizations should patch, review Mobile Access activity, and limit Management Server access where fixes cannot be applied. CISA also added CVE-2026-93952 in Arista VeloCloud Orchestrator and CVE-2026-94127 in F5 Networks’ BIG-IP APM to its Known Exploited Vulnerabilities catalog, highlighting the need to check affected systems for compromise.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store