Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Israeli cybersecurity firm, Check Point, has revealed that attackers exploited a previously unknown flaw in its Security Management Server in a limited number of targeted assaults on July 23rd, the company stated.
Zero-Day Exploit Details
The flaw, identified as CVE-2026-93616, allows an attacker who can access the server's web service to execute scripts on it without logging in. Check Point issued a patch on September 22nd for the server that manages firewall policies for the Check Point product line.
Impact and Recommendations
- The flaw affects Check Point's Security Management Server, which is utilized to control firewall policies for the company's product line.
- Check Point urges all affected users to apply the security update ASAP to prevent potential exploitation.
Background on Check Point
Check Point Software Technologies Ltd. is an Israeli multinational cybersecurity company headquartered in Tel Aviv. The company offers a range of security solutions, including endpoint security, network security, and cybersecurity.
</body> </html><small>Source: The Hacker News — read the original story there.</small>