Two CVSS 9.8 flaws, including a newly disclosed zero-day in Check Point’s Security Management service, gave attackers a path into some of the most trusted systems on the enterprise perimeter.