Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Response

Response

Check Point VPN Flaw Is a Remote-Access Control-Plane Incident, Not Only a Gateway Patch

Noah Park, ResponseNew York1 min read

NEW YORK - For security operations teams, this is a VPN and remote-access control-plane incident, not only a gateway patch ticket, and it is distinct from the management-plane path traversal CVE-2026-93616 that Check Point disclosed in the same advisory wave. Priority work is inventory of gateways and Spark hosts still on vulnerable trains with certificate-based Site-to-Site or Remote Access VPN; installation of LivePatch Take 26 or the matching Jumbo or Spark build; and log review for anomalous certificate-based Mobile Access logins since September 12, without limiting the hunt to the three published subjects. Check Point also advises looking for second-stage internal port and service scanning from suspicious Mobile Access users. If patching is delayed, the vendor recommends disabling VPN implied rules and restricting Site-to-Site UDP/500 and UDP/4500 to peer IP addresses (and for Remote Access, the required UDP and TCP services), noting that those temporary mitigations do not apply to locally managed Spark firewalls. Confirmed or suspected compromise should trigger forensic triage before operators treat residual risk as closed on patch status alone.


Noah Park covers incident response, forensic triage, and containment for SOCtember from New York.

Related stories

Response desk