Attackers Sat Inside Check Point's Firewall Brain for Two Months. The Stock Went Up.
Check Point says attackers held unauthenticated code execution on its Management Server, the machine that writes policy for every gateway it manages, from 23 July to 22 September. The stock spent disclosure week crossing its 200-day average at 13.95 times earnings.
Vincent Jiang · 3 min read
The grep that tells you July happened
Somewhere this week an administrator is running a one-line grep over the logs of the machine that writes firewall policy for the entire company. Check Point's advisory asks for it: the search for oversized login names is how a shop learns whether CVE-2026-93616, a pre-authentication path traversal rated 9.8 out of 10, let a stranger run scripts on the Management Server without a password 1. "You don't need to break the firewall when you can tell it what to allow," says Aaron Beardslee, manager of threat research at Securonix 2.
Attackers held that ground from 23 July until the fix landed on 22 September 13. The same week, the stock crossed its 200-day average 4.
Two months of quiet, then three days of law
CISA put both Check Point flaws, each rated 9.8, into one Known Exploited Vulnerabilities batch on 22 September, giving federal agencies until the 25th under BOD 26-04 35. The vendor's quiet window ran two months 1; the government's remediation window ran three days 35.
The fix does not reach everyone. Every legacy R80 and R81 release is affected and out of support, so the only remediation is an upgrade, not a hotfix 16. A management server patched just far enough to clear September's separate VPN flaw is still inside this bug's range 6.
The exposed thousands are gateways, not the brain
The 13,000-plus internet-exposed Check Point devices counted globally in June 2024 are VPN gateways: the surface of the companion flaw, CVE-2026-85102, not of the compromised management plane 5. That one was patched on 9 September, drew a Dutch NCSC warning of imminent exploitation by the 10th, and, per Check Point's VP of Research Lotem Finkelstein, a wave of attempts against Spark customers from the 12th 78. Management Servers are supposed to never face the internet at all 2.
Two months of quiet access, against three days of federal deadline
Data
| Days | |
|---|---|
| Attacker dwell before fix (23 Jul to 22 Sep) | 61 days |
| Patch to CISA KEV listing (22 Sep) | 0 days |
| CISA remediation window under BOD 26-04 (22 to 25 Sep) | 3 days |
So the greps differ. Gateway shops audit VPN logs back to 12 September 5; management-server shops, where the box was reachable anyway, hunt two months of artifacts 1.
The market paid $141 for the calm
On 24 September the stock crossed its 200-day average of $134.13 and touched $141.29: a $13.92 billion company at 13.95 times earnings 4. The June quarter brought $673.6 million in revenue, up 1.3% year over year, and an EPS beat at $2.55 against $2.45 4.
Revenue is still growing; operating income has fallen year over year for four quarters
- Revenue YoY %
- Operating income YoY %
Data
| Revenue YoY % | Operating income YoY % | |
|---|---|---|
| Q3 '25 | 6.7% | -8.9% |
| Q4 '25 | 5.9% | -8.4% |
| Q1 '26 | 4.8% | -5.3% |
| Q2 '26 | 1.3% | -9.1% |
The AI roadmap never paused
While the zero-day sat quiet, the firm published a digest on AI models escaping their own test containment 10 and wired OpenAI's Daybreak cyber models into Keystone, the same security-management line, some of it already in production 11. Keystone now has to answer whether it inherits the trust model that just burned.
Check Point says model access is restricted and outputs verified before the systems act 11. The blast-radius math is unchanged: "If one console manages fifty gateways, its compromise is fifty times worse than any one gateway's," says Frank Dickson of Dickson Research 2.
The case for the premium
The attacks were pinpointed and hit a handful of customers, and fixes exist for every supported branch 13. Security products are software, and software has bugs 2. Twenty-seven analysts rate the stock a Hold with a $148.74 consensus target, a shrug, not an exit 4.
The premium, for now, stays with Check Point and its holders. The residual risk sits with shops on out-of-support R80 and R81, which have no hotfix to install and an upgrade to budget 16.
Watch the grep, not the ticker
Patching closes the door; it does not evict whoever walked through in July 2. The tell is the first enterprise that finds it. The stock has voted. The logs have not.
How this brief was made
01Gathered & sourced369 channels · 2,130 articles▾
Agents swept 369 channels and ingested 2,130 articles, then de-duplicated and ranked them for signal.
02Verified & cross-validated11 claims · 38 data feeds▾
Every one of 11 load-bearing claims was checked against primary sources, with 38 live data feeds reconciling the figures and charts.
- 1Yahoo Tech, The Control Tower Left Unguarded: Check Point's Management Server Zero-Day Gave Attackers Two Months of Silent Access, 25 September 2026
- 2CSO Online, Check Point hacked: The security software protecting your network has become a prime attack target, September 2026
- 3SecurityWeek, Check Point Patches Exploited Management Server Zero-Day, 22 September 2026
- 4MarketBeat, Check Point Software Technologies (NASDAQ:CHKP) Share Price Breaks Above 200-Day Moving Average, 25 September 2026
- 5Forkast News, The VPN Certificate Bypass That Was Patched in September Is Now Actively Exploited, Federal Deadline Hits Sep 25, 25 September 2026
- 6The Hacker News, Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks, 22 September 2026
- 7BleepingComputer, Check Point warns of hackers exploiting Security Gateway VPN RCE flaw, 23 September 2026
- 8Help Net Security, Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances, 23 September 2026
- 9Sharadar quarterly fundamentals, from Check Point Software's SEC filings, retrieved 27 September 2026
- 10Security MEA, Check Point Reveals AI Models Breached Their Own Containment, 21 September 2026
- 11ET CISO, Check Point integrates OpenAI Daybreak models into security workflows, September 2026
03Reviewed & edited1 human editor▾
One editor read the draft against the evidence, tuned the framing, and signed off before it shipped.
Become a contributor
Reporting on the business of AI and want it read? We take pitches from outside contributors who bring primary sources and a number worth arguing about.
Deepdive
AI-generated from this story and its cited sources. Not investment advice.



