CuraSec

Act active

Check Point Management Server Zero-Day Exploited, Patch Released

2026-09-23 15:27 UTC · The Hacker News · read the source ↗ #check-point#zero-day#rce
  • Engineer — Act: CISA KEV-listed with a public GitHub PoC and confirmed exploitation — patch Check Point Security Management Server to the September 22 fix immediately; the flaw allows unauthenticated script execution on the server that controls your firewall policies.
  • SOC/IR — Act: Exploitation dates to July 23, so sweep Check Point management server access logs for anomalous unauthenticated web service calls and unexpected script executions from that date forward; assume-breach posture is warranted given KEV listing.
  • Leader — Act: If Check Point is in the environment, confirm the management server has been patched to the September 22 release and request a compromise assessment covering activity since July 23 — attacker access here means potential modification of firewall policies across the estate.
  • Signals: CVE-2026-93616 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.