Check Point hacked: The security software protecting your network has become a prime attack target

Summary

Check Point is actively addressing two vulnerabilities in its Security Gateway and Security Management products that are being exploited by attackers. CVE-2026-85102 is a remote code execution vulnerability, and CVE-2026-93616 is a pre-authentication path vulnerability. Both flaws allow attackers to gain access without authentication and are critical to install patches for immediately.

IFF Assessment

FOE

The article details critical vulnerabilities in security software that are actively being exploited, posing a significant threat to defenders.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 25, 2026. Known ransomware use: Unknown.

Defender Context

This article highlights a severe risk where the security product itself, a firewall, has become the attack vector. Defenders must prioritize patching Check Point Security Gateways and Management products immediately to prevent unauthorized access and potential network compromise. This underscores the importance of regularly updating all security infrastructure and staying informed about exploits targeting vendor products.

Read Full Story →