Check Point Software Technologies provides cybersecurity solutions that protect networks, cloud environments, and mobile devices for enterprises, service providers, SMBs, and consumers. Its Check Point Infinity unified security architecture combines threat prevention with centralized security management, spanning on-premises networks, cloud workloads, and remote access. Quantum, CloudGuard, and Harmony are its main products that address network security, cloud security, and remote access respectively. The platform integrates multiple environments into one management console to reduce gaps and simplify security, aiming to deliver ongoing protection for evolving threats while earning recurring subscription revenue.
Company Size
5,001-10,000
Company Stage
IPO
Headquarters
Tel Aviv-Yafo, Israel
Founded
1993
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
401(k) Retirement Plan
401(k) Company Match
Disability Insurance
Life Insurance
Company Equity
Employee Stock Purchase Plan
Clalit, Check Point announce partnership to secure healthcare data of 5m. Israelis with AI systems. The companies explained that the partnership will allow "embedding AI into everyday workflows" in the healthcare provider, while also targeting cybersecurity threats. The Jerusalem Post This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners.
Clalit and Check Point team up to secure AI use across Israel's largest HMO. The multimillion-shekel partnership aims to prevent sensitive patient information from leaking through public AI tools while also protecting against attacks involving autonomous AI agents. Shaked Green Arava 11:00, 27.09.26 How can a doctor be prevented from inadvertently entering a patient's treatment summary into a public platform such as ChatGPT? And how can attackers be stopped from exploiting artificial intelligence to extract sensitive data from a hospital? To address these risks, Clalit and Check Point have signed a multimillion-shekel strategic partnership to develop a security framework that will enable the health fund to expand its use of AI while protecting sensitive information. The initiative comes against a backdrop of conflicting realities in healthcare. On the one hand, employees and medical staff are increasingly turning to tools such as ChatGPT and Gemini to streamline their work. On the other, the rapid digitization of healthcare systems has created new vulnerabilities. Adv. Avivit Kotler, Clalit's CISO, said the organization has faced a dramatic increase in cyber threats. "In recent years, and particularly since the outbreak of the war, we have been experiencing attack attempts from Iran and its proxies at rates hundreds of times higher than usual." "We are talking about tens of thousands of attacks per year," she said. According to Kotler, a turning point came with the ransomware attack that crippled Hillel Yaffe Medical Center, prompting the Ministry of Health to tighten its cybersecurity regulations. Clalit already uses AI, but it has traditionally operated these systems within closed and isolated environments. A World Health Organization report says Clalit currently uses a platform from Aidoc, which is integrated directly into its internal imaging systems to manage medical algorithms, as well as local models that scan historical data to identify previously undiagnosed diseases. These internal systems operate under the health fund's organizational regulations. But the introduction of free, publicly available GenAI applications into clinics has created what Kotler describes as "an additional layer of risk." The concern is uncontrolled use. If a physician copies a medical summary containing personally identifiable information into an external AI-powered search engine, for example, sensitive information could potentially be exposed outside the organization. The security gateway being developed by Clalit and Check Point is intended to prevent such incidents, enforce privacy rules and establish clear "guardrails" that allow staff to use AI tools and derive insights without compromising patient privacy. The system will also have to address more complex and increasingly autonomous threats, including AI agents and third-party applications that connect to hospital systems. An AI agent responsible for automatically scheduling appointments, for example, could potentially gain access to sensitive information that is irrelevant to its task or attempt to transfer that data to an external server. The security gateway is designed to monitor such agents in real time and block anomalous actions by external applications. For Check Point, the partnership provides a large-scale environment for developing and deploying the technology across a healthcare system serving five million people in Israel. In return, Check Point will retain the intellectual property rights, with the goal of eventually commercializing and selling the platform. Despite the close collaboration, Clalit says patient data will remain within the health fund. "The only information Check Point sees is metadata; they have absolutely no access to our patients' data," Kotler said. Kotler estimates that the system will be widely deployed and fully meet the organization's needs by the first quarter of 2027.
Critical Check Point VPN zero-day exploits demand immediate patch. Urgent patches required for critical Check Point VPN and Management server zero-days enabling remote root code execution amid active exploitation. The discovery and exploitation of multiple critical zero-day vulnerabilities targeting Check Point VPN and Security Management servers represents a serious threat to enterprise network security. These vulnerabilities, most notably CVE-2026-85102 and CVE-2026-93616, allow unauthenticated attackers to execute arbitrary remote code with root privileges, compromising network perimeter defenses and management infrastructure. The advanced nature and active use of these flaws by attackers demand immediate attention from cybersecurity teams to prevent potentially widespread breaches. Overview of Check Point VPN and Management server vulnerabilities. CVE-2026-85102 exploits improper certificate validation during VPN negotiation in Check Point Spark Firewalls and Security Gateways. This critical issue permits unauthenticated remote code execution, enabling attackers to bypass standard authentication processes. As Spark Firewalls serve as gateway devices controlling VPN access, successful exploitation threatens the network perimeter, allowing potential manipulation of firewall policies and lateral movement within corporate environments. Simultaneously, CVE-2026-93616 targets Check Point Security Management Servers with a sophisticated path traversal flaw coupled with unsafe file upload handling. This zero-day enables arbitrary script execution without authentication, directly jeopardizing enterprise firewall management and security policy integrity. Because management servers centrally govern security configurations, their compromise could lead to widespread and persistent control by attackers. Both vulnerabilities hold a CVSS score of 9.8, underscoring their severe risk, and have been actively exploited in the wild since at least mid-2026. Attack patterns indicate the use of anonymization services by threat actors to obscure attack origins, emphasizing the advanced and targeted nature of the campaigns. Implications for organizational security posture. The presence of unauthenticated remote root code execution exploits within critical infrastructure components highlights attackers' evolving tactics focused on high-impact targets. Exploitation of CVE-2026-85102 circumvents VPN authentication through certificate validation flaws, allowing adversaries to gain persistent, unauthorized network access. Such access threatens to facilitate credential theft, network reconnaissance, and lateral escalation. In parallel, the exploitation of management server vulnerabilities underscores attackers' intent to undermine centralized security controls. Control over management servers enables modification of firewall policies, insertion of backdoors, and disruption of security monitoring, severely impairing incident response and increasing the risk of extended undetected compromise. Since these vulnerabilities impact both edge devices and central management systems, organizations face multifaceted exposure requiring coordinated mitigation strategies. The active exploitation in targeted attacks illustrates the immediacy of the threat, leaving no margin for delayed responses. Recommended mitigation and response strategies. Timely application of vendor-provided patches is paramount. Check Point has released hotfixes and LivePatch versions addressing CVE-2026-85102; however, for CVE-2026-93616, LivePatch is currently unavailable, emphasizing the urgency of manual patch installation. In addition to patching, security teams are advised to: * Restrict access to management servers, particularly TCP port 19009, to trusted and authenticated IP addresses. * Conduct thorough log analysis focusing on VPN certificate anomalies, suspicious certificate subjects, and evidence of path traversal or unauthorized script execution. * Perform retrospective forensic investigations to detect potential pre-patch exploitation and persistence. * Temporarily adjust VPN access controls, if patching cannot be immediately completed, to limit exposure. * Leverage Indicators of Compromise (IoCs) shared by Check Point and CISA to enhance detection capabilities. Federal agencies are mandated to complete remediation by September 25, 2026, as stated by the Cybersecurity and Infrastructure Security Agency (CISA). However, private sector organizations should equally prioritize these patches and assessments due to the active and global nature of exploitation. Conclusion. The exploitation of critical zero-day vulnerabilities in Check Point VPN and Management Servers signifies a dangerous advancement in attacker techniques, combining unauthenticated remote root code execution with attack stealth facilitated by anonymizing networks. Organizations relying on affected Check Point products must urgently prioritize patch deployment, implement access restrictions, and enhance monitoring to mitigate this high-severity threat. Ignoring these flaws risks losing control over vital network infrastructure components, amplifying potential damage including unauthorized access, lateral movements, and disruption of security operations. The evolving threat landscape demonstrated here reinforces the importance of prompt vulnerability management and continuous situational awareness in safeguarding organizational assets. References: * CISA Known Exploited Vulnerabilities Catalog * Check Point Security Advisories * Industry threat intelligence reports on CVE-2026-85102 and CVE-2026-93616
Hackers exploit critical Check Point VPN flaws to gain Remote Access without login. Check Point has warned that attackers are actively exploiting two critical vulnerabilities in its VPN and management products, allowing unauthenticated remote access and possible remote code execution. Both flaws carry a CVSS severity score of 9.8, and the company has released fixes that affected organizations should apply immediately. The first issue, tracked as CVE-2026-85102, affects Check Point Security Gateway and Spark Firewall deployments that use Remote Access VPN or certificate-based Site-to-Site VPN authentication. The flaw stems from improper validation of certificate data during VPN negotiation, which can allow a remote attacker to execute arbitrary code without valid credentials. Check Point released a patch for CVE-2026-85102 on September 9, 2026. At that time, the company had not identified exploitation activity. Check Point VPN flaws exploit. However, Check Point later confirmed that attackers began attempting to exploit the vulnerability against Spark Firewall customers from September 12. The attacks were observed globally and originated from anonymization infrastructure, including VPN services and proxy networks. Attackers used suspicious VPN certificate subject values such as CN=vpn, OU=users, O=global; CN=vpn-user, OU=users, O=global; and CN=vpnuser, OU=users, O=global. These indicators should not be treated as a complete detection list, as threat actors may use different certificate subjects in future attempts. The second flaw is a newly disclosed zero-day vulnerability (CVE-2026-93616) affecting Check Point Security Management and Multi-Domain Security Management environments. It is a pre-authentication directory traversal and file-upload issue that can enable an attacker to upload and execute arbitrary scripts on an exposed management server. Check Point said it knows of a handful of customers targeted in real-world attacks. CVE-2026-93616 affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products. Smart-1 Cloud, Check Point Firewall Appliances, and Check Point Spark Firewall are not affected by this management-server vulnerability. The flaw can allow an unauthenticated attacker to abuse directory traversal sequences, such as .../, to access unintended paths and load attacker-controlled content. In practical terms, successful exploitation could give an intruder a path to execute malicious scripts on a highly privileged management platform, creating risks of firewall policy manipulation, credential theft, network reconnaissance, and lateral movement. Organizations using vulnerable Check Point products should install the available Jumbo Hotfixes or security hotfixes without delay. For CVE-2026-85102, Check Point protects LivePatch Take 26 or later supported Jumbo Hotfix releases. The company notes that R82.20 is not affected by this VPN issue. For CVE-2026-93616, administrators should update to the R82.20 Security Hotfix or supported Jumbo Hotfix versions. Check Point said LivePatch Take 28 and Take 29 do not address this vulnerability, and a LivePatch is not available because of the nature of the required fix. Administrators should review Mobile Access logs for anomalous certificate-based VPN logins and investigate suspicious activity performed by newly authenticated users. Internal port scanning or service discovery after a questionable VPN login may indicate second-stage intrusion activity. For management servers, Check Point recommends restricting TCP port 19009 access to trusted IP addresses only. Security teams should also inspect management logs for unusually long usernames, error messages involving ReflectionUtils, and file paths containing directory traversal patterns. These artifacts may signal an attempted exploit against CVE-2026-93616. The active exploitation of both flaws highlights the continuing value of patching internet-facing VPN and security-management infrastructure quickly. These systems often sit at the network perimeter or control critical security policies, making them high-value targets for ransomware operators, access brokers, and state-backed threat actors. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post hackers exploit critical Check Point VPN flaws to gain Remote Access without login appeared first on Cyber Security News. Related Cyber Security News posts. Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote code execution under specific conditions. Check Point's own research team uncovered the flaws, and the company says it has found no... In "Cybersecurity News - Original News Source is cybersecuritynews.com" The Dutch National Cyber Security Center (NCSC) has issued an urgent warning over two critical vulnerabilities in Check Point VPN products, saying it expects large-scale exploitation attempts in the near term. Organizations using affected Check Point gateways, management systems, or Spark Firewall products should deploy the available fixes immediately. Tracked... In "Cybersecurity News - Original News Source is cybersecuritynews.com" June 8, 2026 Check Point Research has uncovered active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability (CVSS 9.3) in Check Point Remote Access VPN and Mobile Access deployments, with confirmed post-compromise activity linked to the Qilin ransomware gang. CVE-2026-50751 targets deployments configured to use the deprecated IKEv1 key exchange... In "Cybersecurity News - Original News Source is cybersecuritynews.com"
Check Point Software appoints Krishnan V V as MD for India, South Asia. Check Point Software Technologies | Image: X Cybersecurity solutions provider Check Point Software Technologies on wednesday announced the appointment of Krishnan V V as its managing Director and Country head for India and South Asia, effective immediately. In his new role, Krishnan will oversee the company's business strategy, profit and loss (P&L) performance, go-to-market execution, and organisational development across the region, according to a company statement. He will report to Ruma Balasubramanian, President, Asia Pacific & Japan (APAC & Japan), the company said. Krishnan brings over three decades of leadership experience. Before joining Check Point, he served as Country Director - BFSI at Palo Alto Networks. He has also previously held senior leadership positions at several companies, including Wipro, Sun Microsystems, Oracle, Symantec and Seclore. "India sits at the centre of many of the world's most important technology and business transformations. As AI adoption accelerates, organisations are looking for security partners that can simplify complexity while delivering comprehensive protection across networks, cloud environments, workspaces and AI systems. "Krishnan combines strong customer and partner relationships, deep cybersecurity expertise and a proven track record of leadership, making him ideally positioned to lead Check Point's next chapter of growth in India and South Asia," Balasubramanian said. (Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)