{"id":9571,"date":"2026-09-24T02:05:30","date_gmt":"2026-09-24T02:05:30","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9571"},"modified":"2026-09-24T02:05:30","modified_gmt":"2026-09-24T02:05:30","slug":"check-point-hacked-the-security-software-protecting-your-network-has-become-a-prime-attack-target","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9571","title":{"rendered":"Check Point hacked: The security software protecting your network has become a prime attack target"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">A firewall is supposed to be the barrier between attackers and the enterprise network, but that barrier can itself become a threat actors\u2019 tool. Check Point has revealed that attackers are <a href=\"https:\/\/blog.checkpoint.com\/security\/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616\/\" target=\"_blank\" rel=\"noopener\">actively exploiting<\/a> two vulnerabilities in its Security Gateway and Security Management products.<\/p>\n<p class=\"wp-block-paragraph\">The security software provider has warned that attackers are targeting <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-85102\" target=\"_blank\" rel=\"noopener\">CVE-2026-85102<\/a>, a remote code execution (RCE) vulnerability in its Check Point Spark small business firewall disclosed on September 9. It also discovered a zero-day pre-authentication path vulnerability, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-93616\" target=\"_blank\" rel=\"noopener\">CVE-2026-93616<\/a>, in its Security Management web service.<\/p>\n<p class=\"wp-block-paragraph\">Fixes are available for both vulnerabilities, and Check Point advises customers to install them immediately.<\/p>\n<p class=\"wp-block-paragraph\">\u201cBoth are rated CVSS 9.8, and both let an attacker in without a username or password, which puts them in the worst category a firewall vendor can have,\u201d said <a href=\"https:\/\/dicksonresearch.com\/\" target=\"_blank\" rel=\"noopener\">Frank Dickson<\/a> of Dickson Research.<\/p>\n<h2 class=\"wp-block-heading\">Handing attackers skeleton keys<\/h2>\n<p class=\"wp-block-paragraph\">Both flaws are pre-authentication, meaning an attacker never needs a username, password, or stolen session, explained <a href=\"https:\/\/www.linkedin.com\/in\/aaron-beardslee\" target=\"_blank\" rel=\"noopener\">Aaron Beardslee<\/a>, manager of threat research at Securonix.<\/p>\n<p class=\"wp-block-paragraph\">With CVE-2026-85102, the trigger arrives during initial VPN negotiation; the attacker need only hand the gateway a malicious certificate and the gateway does the rest. \u201cThe gateway is the front door, the lock, and the security guard all in one box,\u201d Beardslee said.<\/p>\n<p class=\"wp-block-paragraph\">Code execution puts attackers on the trusted side of the perimeter, sitting on the very system that brokers <a href=\"https:\/\/www.csoonline.com\/article\/4224418\/the-cyber-ai-parity-window-now-has-a-deadline.html\" target=\"_blank\" rel=\"noopener\">remote access<\/a> for every employee. \u201cIn plain terms, the attackers are walking through the VPN and immediately mapping the internal network,\u201d he said.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-93616 could allow attackers to execute scripts from an arbitrary path and load an arbitrary Java class. Beardslee called it \u201carguably worse in impact,\u201d even though exploitation so far has been narrow, because the management server is effectively the \u201cbrain\u201d of a Check Point deployment.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt writes and pushes policy to every gateway,\u201d he said, so an attacker who accesses it could theoretically rewrite firewall rules, open paths into the network, and harvest configuration data about the entire architecture.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou don\u2019t need to break the firewall when you can tell it what to allow,\u201d Beardslee said. He also pointed to the timeline: Check Point observed a few targeted attacks on July 23, but the fix didn\u2019t ship until two months later, a huge window of zero-day exposure on \u201cthe most privileged box in the security stack.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Dickson agreed that CVE-2026-93616 is the worst of the two in a \u201cstructural sense,\u201d because an attacker who gets into one gateway has a foothold in the system. This gives them \u201cthe keys to every gateway that server controls,\u201d he said. \u201cThat\u2019s the difference between picking one lock and stealing the master key to the whole building.\u201d<\/p>\n<h2 class=\"wp-block-heading\">The security software conundrum<\/h2>\n<p class=\"wp-block-paragraph\">These vulnerabilities make it clear that security products, although meant to protect, are not immune to <a href=\"https:\/\/www.csoonline.com\/article\/4223011\/16-governance-tools-for-securing-your-ai-fleet.html\" target=\"_blank\" rel=\"noopener\">security flaws<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">\u201cSecurity products are software, and software has bugs,\u201d Beardslee pointed out. Yet organizations tend to treat firewalls and their management consoles as appliances they set up and trust, not as internet facing servers that require the same scrutiny as anything else.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAttackers see it the other way,\u201d he said. These devices are exposed by design, highly privileged, and rarely instrumented with the endpoint telemetry that is demanded on, say, a Windows server. \u201cThat combination makes them some of the most attractive targets in the enterprise,\u201d Beardslee said. Path traversal, the class behind CVE-2026-93616, is one of the oldest web bugs around.<\/p>\n<p class=\"wp-block-paragraph\">\u201cSeeing it pre-auth on a management service in 2026 is a reminder that simple hacks are sometimes the best hacks,\u201d he noted.<\/p>\n<p class=\"wp-block-paragraph\">Dickson agreed that the device whose job is keeping attackers out is also, by definition, exposed to the internet and trusted by everything behind it. This \u201cmakes it the single most valuable target on the network.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Ultimately, he pointed to the speed of today\u2019s security landscape: Check Point patched CVE-2026-85102 on September 9, and attackers were exploiting the flaw by September 12.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThree days is now a normal window for attackers to reverse-engineer a patch into a working exploit,\u201d he said. This, he noted, means that \u201cwe\u2019ll patch it during the next maintenance cycle\u201d is no longer an acceptable timeline for anything sitting on the perimeter.<\/p>\n<p class=\"wp-block-paragraph\">But this isn\u2019t an isolated occurrence, and the common thread isn\u2019t any one vendor\u2019s code quality. <a href=\"https:\/\/www.csoonline.com\/article\/4225721\/f5-fixes-actively-exploited-zero-day-flaw-in-big-ip-apm.html\" target=\"_blank\" rel=\"noopener\">F5 access policy manager zero-days<\/a> were under active attack in the same week as they were revealed, and both companies\u2019 vulnerabilities landed on the KVE catalog on the same day. Perimeter security appliances, firewalls, VPN gateways, and management consoles are a preferred first target for serious attackers precisely because they were built to be trusted, not because they were built carelessly.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEdge security appliances are simultaneously the most trusted and the most exposed thing on a network,\u201d he said. \u201cThat combination is exactly what makes them worth an attacker\u2019s time.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Advice for enterprises<\/h2>\n<p class=\"wp-block-paragraph\">Check Point advises customers to review logs for anomalous certificate-based Mobile Access logins and second-stage activity, such as internal port or device scans, from suspicious logged-in users.<\/p>\n<p class=\"wp-block-paragraph\">Dickson goes a step further, urging enterprises to get management off the public internet altogether if possible. \u201cA pre-auth path traversal is only remotely exploitable if the management console is reachable to begin with,\u201d he pointed out.<\/p>\n<p class=\"wp-block-paragraph\">Also, \u201chunt, don\u2019t just patch,\u201d he said. Search now for patterns identified by Check Point, rather than assuming a patched system was never touched. Treat the management plane\u2019s blast radius as a design question, not an afterthought. \u201cIf one console manages fifty gateways, its compromise is fifty times worse than any one gateway\u2019s, and that ratio is worth revisiting,\u201d Dickson said.<\/p>\n<p class=\"wp-block-paragraph\">Further, give perimeter and security infrastructure its own patch service level agreement (SLA) measured in days, separate from that of the general IT patch cycle that measures in weeks. Keep an eye on the Known Exploited Vulnerabilities (KVE) catalog as an operational signal rather than as a compliance checkbox.<\/p>\n<p class=\"wp-block-paragraph\">\u201cLanding on it, as both of these did on September 23, is a strong sign the exploitation is real and ongoing,\u201d Dickson said.<\/p>\n<p class=\"wp-block-paragraph\">Beardslee emphasized that any code running pre-auth should be \u201ctreated as hostile territory.\u201d Keep it minimal, parse in memory safe code where possible, and fuzz relentlessly, he advised. Don\u2019t assume automatic patching covers you; verify versions and hotfix takes on every management server by hand.<\/p>\n<p class=\"wp-block-paragraph\">Also, be aware that IP blocklists won\u2019t save you here. Attempts originate from anonymization infrastructure, including VPN services and proxies. \u201cThe indicators rotate. Behavior doesn\u2019t,\u201d Beardslee said.<\/p>\n<p class=\"wp-block-paragraph\">Security management web interfaces have no business being reachable from the internet, he noted. Put them behind allowlists or a dedicated admin network, and a pre-auth bug becomes far harder to reach. In the case of VPN gateways that must face the internet, the focus should shift to visibility.<\/p>\n<p class=\"wp-block-paragraph\">Also, admins should retire end-of-support versions of software and hunt on behavior, not just the indicators. A certificate login never seen before, followed by scanning from the VPN address pool, is the pattern that matters, he noted. Forward gateway and management logs to a security information and event management (SIEM) platform and actually hunt within them. Check Point has published certificate subjects seen in the attacks, but also warned that the list is not exhaustive.<\/p>\n<p class=\"wp-block-paragraph\">\u201cHunt backward for signs of compromise, because patching closes the door, but doesn\u2019t evict anyone already inside, taking their time hacking through your infrastructure,\u201d Beardslee said.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A firewall is supposed to be the barrier between attackers and the enterprise network, but that barrier can itself become a threat actors\u2019 tool. Check Point has revealed that attackers are actively exploiting two vulnerabilities in its Security Gateway and Security Management products. The security software provider has warned that attackers are targeting CVE-2026-85102, a [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9572,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9571","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9571"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9571"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9571\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9572"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9571"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9571"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9571"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}