# CISA adds two exploited Check Point flaws to federal fix list

_Published Wednesday, September 23, 2026 at 5:08 PM EDT · Security, Infrastructure · Latest · Tier 1 — Major_

![CISA adds two exploited Check Point flaws to federal fix list — Primary](https://www.bleepstatic.com/content/hl-images/2026/07/23/Check-Point.jpg)

The U.S. Cybersecurity and Infrastructure Security Agency added two Check Point Security Gateway flaws to its list of known exploited vulnerabilities and told federal agencies to apply fixes or mitigations by September 25. Check Point confirmed active exploitation of a VPN flaw that can let an unauthenticated attacker execute code remotely. It also warned that attackers have exploited a separate Management web service flaw since July 23.

Check Point says attacks against Spark customers began September 12. It recommends updated software or patches for affected gateways and firewalls. Customers who installed an earlier offline patch package need a newer version for full coverage.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/)

---
Canonical: https://techandbusiness.org/newswire/llQKgxbMlEHd9r0NQIrR1U
Published: 2026-09-23T21:08:29.309Z
Story chronology: 2026-09-23T19:53:54.000Z
Retrieved: 2026-09-23T22:30:01.950Z
Publisher: Tech & Business (techandbusiness.org)
