Two of the boxes that sit between your business and the internet are being hit right now. Check Point disclosed critical VPN certificate flaws in its Security Gateway and Spark Firewall products on 9 September, and by 12 September a wave of real exploitation attempts had started against Spark customers specifically — the firewall line Check Point sells to small and medium-sized businesses and the managed service providers who support them. This week, researchers confirmed the same attackers are also going after Check Point Management Servers and F5 BIG-IP APM appliances, the latter via a separate, newly-disclosed zero-day that lets an unauthenticated attacker run code on systems handling OAuth logins. Both vulnerabilities carry a CVSS score of 9.8 out of 10 — about as severe as it gets.
What makes this worth acting on today rather than filing away is who’s being targeted. This isn’t a niche enterprise-only issue. Spark is explicitly the “SME firewall,” and a lot of smaller UK businesses have one sitting at the edge of their network without a dedicated IT team watching it closely. Attackers are routing their exploitation attempts through VPN services and proxies to mask where they’re coming from, which suggests a deliberate, sustained campaign rather than opportunistic scanning.
Check what you’re running, today
Start with a simple inventory question: does your business, or your IT provider, use a Check Point Security Gateway, a Check Point Spark firewall, or an F5 BIG-IP device anywhere in your network? If you don’t know, that’s the first thing to find out — ask whoever manages your network hardware directly, don’t assume “someone else handles that.” If the answer is yes, check whether the September patches have actually been applied, not just scheduled. Check Point’s fix for the Spark and Security Gateway flaws has been available since 9 September; F5 released hotfixes for the BIG-IP APM issue on 22 September. Unpatched systems past those dates are sitting exposed to a campaign that’s already live.
Don’t treat “patched” as “done”
Because exploitation started before some organisations had patched, a clean patch alone doesn’t rule out prior compromise. If your device was internet-facing and unpatched at any point after 9 or 12 September, it’s worth a proper look at logs and configuration for signs of unauthorised access, not just applying the update and moving on. This is exactly the kind of gap between “we think we’re fine” and “we’ve actually checked” that catches SMEs out — a service like KeepSafe’s incident monitoring exists precisely to flag unusual activity on business systems before it turns into a full breach, rather than after.
If you don’t have the in-house expertise, say so
Plenty of small businesses inherited their firewall setup from a previous IT contractor or an early hire who’s since moved on, and nobody currently on staff feels confident touching the config. That’s a normal position to be in, but it’s not a safe one to stay in during an active exploitation wave. If patching, log review, or even just confirming what hardware you’re running feels beyond what your team can do quickly and correctly, get a technical specialist to look at it this week rather than next month — CoolCoding’s technical implementation work covers exactly this kind of urgent, hands-on infrastructure check.
The takeaway
Two widely-used firewall and VPN platforms have live, actively-exploited vulnerabilities right now, and one of them — Check Point Spark — is sold specifically to businesses your size. Find out today what’s protecting your network, confirm the relevant patch is actually installed, and if there’s any chance it sat unpatched during the exploitation window, get someone to check for signs of compromise rather than assuming the patch alone has closed the door.