Check Point Research (2026-09-22) warns of active exploitation of two critical issues. CVE-2026-93616 is a newly disclosed pre-authentication path traversal in the Security Management web service (also Multi-Domain management, Log Server, SmartEvent) — CVSS 9.8 — that lets an unauthenticated attacker upload/execute arbitrary scripts and load Java classes. Fix is in the advisory Jumbo/hotfixes (sk1000171); LivePatch Take 28/29 does not cover it. Smart-1 Cloud is already patched; gateways/Spark firewalls are not in scope for this CVE. CISA added it to KEV on Sep 22 with FCEB remediation due 2026-09-25. Separately, CVE-2026-85102 (VPN certificate RCE on Security Gateway/Spark, fix since Sep 9) is seeing exploitation attempts against Spark customers since about Sep 12.
Same day, BleepingComputer / Microsoft DCU: EvilTokens (Storm-2992) — a phishing-as-a-service platform that specialized in OAuth device-code phishing that bypasses MFA — was disrupted after compromising more than 12,000 Microsoft accounts across 10,000+ organizations (SpyCloud: ~8,700 recaptured accounts / 6,585 domains). The service used AI to customize lures and mine inboxes for BEC targets; list price cited at $500/month or $1,500 one-time. Microsoft seized infrastructure with Health-ISAC, SpyCloud, and UK law enforcement (two arrests). Microsoft says this was a disruption, not a full kill — clones such as APToken already exist.
Livermore takeaway: if you run Check Point management on-prem, patch today and hunt per sk1000171 — do not assume LivePatch covered you. For M365 shops, disable device-code auth where it is not required, prefer FIDO2/passkeys, and treat unexpected “enter this code at microsoft.com” prompts as credential theft.