Bg ShapeBg Shape
THREAT INTELLIGENCE

Check Point Security Gateway VPN and Management Web Service Active Exploitation

Affected Environment
Check Point Security Gateway, Spark Firewall, and Security Management Server across R80 through R82.20 branches.

Threat Overview
Improper certificate validation in VPN negotiation and a path traversal flaw enable unauthenticated remote code execution.

Exposure Timeline
Exploitation against Spark customers began 12 September 2026; the management web service flaw is also actively exploited.

Attack Surface
Site-to-Site and Remote Access VPN certificate authentication, and the management web service's TCP/19009 endpoint.

Technical Root Cause
Improper validation of certificate data during VPN negotiation, and directory traversal enabling arbitrary script upload.

Exploitation Pathway
Attacker presents a crafted VPN certificate or uploads a malicious script via path traversal to execute code.

Operational Impact
Unauthenticated remote code execution on Security Gateways and full compromise of management servers.

Strategic Impact
Critical for all sectors given Check Point's central role in perimeter and VPN security.

Required Mitigation
Apply Check Point LivePatch or Jumbo Hotfix Accumulator updates immediately; restrict Trusted Clients to internal IPs.

Incident Response Guidance
Check for anonymization-linked VPN certificate subjects and review SmartConsole audit logs for application token authentication.

References
Check Point Security Advisory blog; sk1000171; sk1000117.

Download the Full Report

Explore More of the Latest Threat Intelligence

Trusted by clients worldwide

Logo
Logo
Logo
Logo
Logo
Logo

Your 24/7 Security Partner

Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.

Awards Image
Awards Image
Awards Image
Awards Image
Awards Image
Awards Image