DEV Community

Cover image for Check Point VPN Gateways and Management Server Flaws Actively Exploited
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Check Point VPN Gateways and Management Server Flaws Actively Exploited

Summary

Check Point confirmed active exploitation of three critical vulnerabilities (CVE-2026-85102, CVE-2026-85103, and CVE-2026-93616) affecting VPN gateways and management servers, prompting a 72-hour US federal remediation deadline.

Take Action:

If you run Check Point Security Gateways, Spark Firewalls or Security Management Servers, patch immediately to LivePatch Take 26 or the latest Jumbo Hotfix. Older unsupported versions R80 through R81.10 must be upgraded first. Make sure the management server's web interface is reachable only from trusted internal networks. Patching isn't enough, since attackers have been active since September 12: check your VPN logs for unknown sessions and internal LDAP scanning, and if you find anything suspicious, treat the device as compromised and escalate to your incident response team.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)