Check Point security patch release for CVE-2026-93616
Security Patch Release
Summary
Hide ▲
Show ▼
Check Point released R82.20 Security Hotfix (TAR) and updated Jumbo Hotfix Accumulator packages to fix CVE-2026-93616, a Management Server zero-day exploited in the wild. The fixes cover R82.10, R82, R81.20, and R81.10, extending remediation across multiple product branches. Check Point said customers should install the patches immediately and restrict management access behind a firewall or security gateway. The company also warned that LivePatch does not resolve the flaw.
Related Happenings
Check Point VPN certificate mitigation guidance
Advisory/Mitigation
H score53
First: 10.09.2026 14:45
Last: 10.09.2026 14:45
Sources 1
About this happening:
Check Point directed affected customers to Live Patch or the latest Jumbo Hotfix for its VPN certificate flaws, with rollout beginning on September 9. The guidance...
Check Point VPN certificate mitigation guidance
Advisory/MitigationAbout this happening: Check Point directed affected customers to Live Patch or the latest Jumbo Hotfix for its VPN certificate flaws, with rollout beginning on September 9. The guidance...
Check Point VPN certificate security patch release (CVE-2026-85102, CVE-2026-85103)
Security Patch Release
H score53
First: 10.09.2026 14:45
Last: 10.09.2026 14:45
Sources 1
About this happening:
Check Point began delivering fixes on September 9 for CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate flaws in Security Gateways and Secu...
Check Point VPN certificate security patch release (CVE-2026-85102, CVE-2026-85103)
Security Patch ReleaseAbout this happening: Check Point began delivering fixes on September 9 for CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate flaws in Security Gateways and Secu...
Latest development: 22.09.2026 21:29
Check Point said attackers have been trying since September 12 to exploit CVE-2026-85102, a VPN certificate flaw fixed on September 9, and the attempts have targeted customers of Spark, its firewall line for small businesses. The activity came from anonymizing infrastructure, including VPN services and proxies, and used certificate subjects such as CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global, and CN=vpnuser,OU=users,O=global.
HPE ArubaOS-CX security bulletin (CVE-2026-73749)
Security Patch Release
H score31
First: 03.09.2026 21:28
Last: 03.09.2026 21:28
Sources 1
About this happening:
HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code...
HPE ArubaOS-CX security bulletin (CVE-2026-73749)
Security Patch ReleaseAbout this happening: HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code...
Adobe security patch release for CVE-2026-48362
Security Patch Release
H score43
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48362
Security Patch ReleaseAbout this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
SonicWall security patch release for CVE-2026-15409
Security Patch Release
H score54
First: 15.07.2026 00:23
Last: 15.07.2026 00:23
Sources 1
About this happening:
SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
SonicWall security patch release for CVE-2026-15409
Security Patch ReleaseAbout this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
Timeline
-
23.09.2026 09:14 2 articles · 0h ago
Check Point releases hotfixes for exploited Management Server zero-day
Mitigation Patch UpdateCheck Point released the R82.20 Security Hotfix (TAR) and Jumbo Hotfix Accumulator fixes for R82.10 (Take 45), R82 (Take 127), R81.20 (Take 170), and R81.10 (Take 192) after confirming that CVE-2026-93616 is being exploited in the wild against Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products. The company said it was aware of a handful of customers who had been attacked, released indicators of compromise to support hunting, and advised limiting Management Server access behind a security gateway or firewall and restricting TCP/19009 to trusted IP addresses.
Show sources
- Check Point Patches Exploited Management Server Zero-Day — www.securityweek.com — 23.09.2026 09:14
- Check Point Patches Exploited Management Server Zero-Day — www.securityweek.com — 23.09.2026 09:14