

Affected Environment
Check Point Security Gateway, Spark Firewall, and Security Management Server across R80 through R82.20 branches.
Threat Overview
Improper certificate validation in VPN negotiation and a path traversal flaw enable unauthenticated remote code execution.
Exposure Timeline
Exploitation against Spark customers began 12 September 2026; the management web service flaw is also actively exploited.
Attack Surface
Site-to-Site and Remote Access VPN certificate authentication, and the management web service's TCP/19009 endpoint.
Technical Root Cause
Improper validation of certificate data during VPN negotiation, and directory traversal enabling arbitrary script upload.
Exploitation Pathway
Attacker presents a crafted VPN certificate or uploads a malicious script via path traversal to execute code.
Operational Impact
Unauthenticated remote code execution on Security Gateways and full compromise of management servers.
Strategic Impact
Critical for all sectors given Check Point's central role in perimeter and VPN security.
Required Mitigation
Apply Check Point LivePatch or Jumbo Hotfix Accumulator updates immediately; restrict Trusted Clients to internal IPs.
Incident Response Guidance
Check for anonymization-linked VPN certificate subjects and review SmartConsole audit logs for application token authentication.
References
Check Point Security Advisory blog; sk1000171; sk1000117.
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




