<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Check Point on PhllapsNET</title>
    <link>https://www.phllaps.net/tags/check-point/</link>
    <description>Recent content in Check Point on PhllapsNET</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <lastBuildDate>Tue, 22 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.phllaps.net/tags/check-point/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Check Point Multiple Products Improper Certificate Validation Vulnerability</title>
      <link>https://www.phllaps.net/posts/check-point-multiple-products-improper-certificate-validation-vulnerability/</link>
      <pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/check-point-multiple-products-improper-certificate-validation-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.8&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.8 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-09-22) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-85102.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-85102 is an improper certificate validation flaw in Check Point Security Gateway and Check Point Spark Firewall, triggered during VPN negotiation. Both Site-to-Site VPN and Remote Access VPN configurations are affected.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Check Point Multiple Products Path Traversal Vulnerability</title>
      <link>https://www.phllaps.net/posts/check-point-multiple-products-path-traversal-vulnerability/</link>
      <pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/check-point-multiple-products-path-traversal-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.8&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.8 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-09-22) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-93616.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-93616 is a path traversal vulnerability affecting several Check Point management components: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. It combines directory traversal with a file upload flaw, allowing an unauthenticated attacker to write arbitrary files outside the intended upload location and then have them executed as scripts.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
