Check Point hacked: The security software protecting your network has become a prime attack target
Brief
A firewall is supposed to be the barrier between attackers and the enterprise network, but that barrier can itself become a threat actors’ tool. Check Point has revealed that attackers are actively exploiting two vulnerabilities in its Security Gateway and Security Management products.
The security software provider has warned that attackers are targeting CVE-2026-85102 , a remote code execution (RCE) vulnerability in its Check Point Spark small business firewall disclosed on September 9. It also discovered a zero-day pre-authentication path vulnerability, CVE-2026-93616 , in its Security Management web service.
Fixes are available for both vulnerabilities, and Check Point advises customers to install them immediately.
