CyberSecurity SEE

Hackers Exploit Check Point VPN Remote Code Execution and Management Zero-Day in Attacks

Hackers Exploit Check Point VPN Remote Code Execution and Management Zero-Day in Attacks

Check Point Warns of Critical Vulnerabilities Impacting VPN and Security Management Products

Check Point has issued a warning to its customers regarding the exploitation of two critical vulnerabilities discovered within its VPN gateway and Security Management products. The vulnerabilities are identified as CVE-2026-85102 and CVE-2026-93616, both of which carry an alarming CVSS score of 9.8. These vulnerabilities facilitate pre-authentication attacks, thus making immediate patching and mitigation efforts crucial for users of the affected systems.

Understanding the Vulnerabilities

CVE-2026-85102 pertains to an improper certificate validation vulnerability that affects Check Point’s Security Gateway and Spark Firewall VPN deployments. This particular flaw presents a significant risk as it allows unauthenticated remote attackers to execute arbitrary code during the VPN negotiation process. This vulnerability is particularly concerning for both Remote Access and certificate-enabled Site-to-Site VPN configurations, which are prevalent in many organizations.

In response to the vulnerability, Check Point released a fix on September 9. However, just days later, on September 12, the company began observing exploitation attempts targeting Spark Firewalls. Notably, these attacks were traced back to anonymization infrastructures such as VPN services and proxy networks. Some of the malicious certificates involved in the attacks bore subject names including “CN=vpn,” “OU=users,” and “O=global,” indication of the potential sophistication behind the attempts.

Check Point has advised that the list of indicators for identifying these potential threats is not exhaustive, urging defenders to scrutinize any unusual certificate-based logins associated with Mobile Access. The implicated VPN products encompass Security Gateways and Spark Firewall devices that are managed either centrally or locally and running versions R81 through R82.10, including various end-of-support releases. However, it is important to note that version R82.20 is not subject to vulnerabilities associated with CVE-2026-85102. The patch for this vulnerability can be accessed through Check Point LivePatch Take 26, specific Jumbo Hotfix Accumulators, and updated Spark Firewall builds.

The Second Flaw: A Directory Traversal Vulnerability

The second vulnerability, CVE-2026-93616, represents a pre-authentication directory traversal and file upload vulnerability impacting Check Point’s Management web services. This flaw enables unauthenticated attackers to upload and execute arbitrary scripts on a compromised Management Server. Although Check Point has noted that only a limited number of targeted attacks have been documented, the potential implications of this vulnerability are substantial.

This issue has ramifications for various installations, including Security Management Servers, Multi-Domain Security Management Servers, Log Servers, Multi-Domain Log Servers, and SmartEvent installations. However, it is worth clarifying that Smart-1 Cloud, Check Point Firewall Appliances, and Spark Firewalls are not affected by this particular vulnerability. Vulnerable versions include R82.20, R82.10 with Jumbo Hotfix Take 44 or earlier, R82 with Take 126 or earlier, R81.20 with Take 166 or earlier, and older end-of-support releases. Unlike the VPN vulnerability, CVE-2026-93616 cannot be addressed through LivePatch Take 28/29, as Check Point has indicated that a LivePatch is not an available option due to the unique nature of this specific fix.

Recommended Action Steps

In light of these vulnerabilities, organizations employing Check Point products are urged to take immediate action. The recommended steps include:

  1. Applying Available Security Hotfixes: It is crucial for organizations to apply the available security hotfixes or updated Jumbo Hotfix Accumulators as soon as possible.

  2. Restrict Access: Access to the Security Management Server should be restricted behind a Check Point gateway or firewall to minimize risk.

  3. Limit Access to Trusted IPs: Organizations should enforce strict access controls, limiting access to TCP/19009 to only trusted IP addresses.

  4. Review Logs for Suspicious Activity: Vigilant review of Mobile Access and VPN logs is advised, specifically looking for any suspicious authentication events correlated with certificates.

  5. Analyze Logs and Core Dumps: A review of logs such as cpm.elg should focus on identifying unusually long usernames, while associated FWM/MDS core dumps should be analyzed for errors indicative of directory traversal attempts.

These two vulnerabilities highlight the increasing risks faced by internet-exposed VPN and management infrastructures. Organizations that have postponed patching efforts ought to prioritize addressing these vulnerabilities as part of their incident response protocols, especially those that offer remote-access services or have centralized security management servers accessible from outside their network. Prompt and effective remediation can help mitigate potential breaches and safeguard sensitive data from exploitation.

Source link

Exit mobile version