Act
active
Check Point Management Server Zero-Day Exploited, Patch Released
- Engineer — Act: CISA KEV-listed with a public GitHub PoC and confirmed exploitation — patch Check Point Security Management Server to the September 22 fix immediately; the flaw allows unauthenticated script execution on the server that controls your firewall policies.
- SOC/IR — Act: Exploitation dates to July 23, so sweep Check Point management server access logs for anomalous unauthenticated web service calls and unexpected script executions from that date forward; assume-breach posture is warranted given KEV listing.
- Leader — Act: If Check Point is in the environment, confirm the management server has been patched to the September 22 release and request a compromise assessment covering activity since July 23 — attacker access here means potential modification of firewall policies across the estate.
- Signals: CVE-2026-93616 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.