Check Point hacked: The security software protecting your network has become a prime attack target
Attackers are exploiting two pre-authentication Check Point firewall flaws rated CVSS 9.8.
Check Point said attackers are actively exploiting CVE-2026-85102, a pre-authentication remote code execution flaw in Spark small-business firewalls triggered by a malicious certificate during VPN negotiation, and CVE-2026-93616, a pre-authentication path-traversal zero-day in the Security Management web service that can execute scripts and load an arbitrary Java class. Both are rated CVSS 9.8. Targeted attacks on the management flaw were observed on 23 July, with a fix about two months later; the Spark bug was patched on 9 September and exploited by 12 September. Both were added to the known-exploited vulnerability catalog, and Check Point urges immediate patching plus hunts for anomalous certificate logins and internal scans.