Opens in a new tab

Check Point Patches Critical Management Server Zero-Day Exploited in the Wild

  • Home
  • Blog
  • Check Point Patches Critical Management Server Zero-Day Exploited in the Wild
Check Point zero-day patch sealing a breached management Server with a metallic shield

Check Point has released urgent patches for a critical-severity vulnerability in Management Server that attackers are exploiting as a zero-day. The flaw, tracked as CVE-2026-93616 with a CVSS score of 9.8, allows unauthenticated attackers to upload and execute arbitrary scripts on the management host, giving them a direct path into the systems that control an organization’s security policies and logs.

Applying the newly released hotfix closes the door on that path and stops active exploitation attempts already observed against customer environments.

What Is CVE-2026-93616?

CVE-2026-93616 is a directory traversal and file upload vulnerability in Check Point’s Security Management Server. The defect allows an unauthenticated attacker to upload arbitrary files and execute scripts on the management host. Because the Management Server sits at the center of policy, log, and event management for Check Point deployments, a compromise there gives an attacker broad control over the surrounding security infrastructure.

Check Point’s advisory confirms that a handful of customers have already been attacked through this flaw, which is why the patch was released as an urgent hotfix rather than a routine update.

Which Products Are Affected?

The vulnerability impacts several core Check Point management and logging products:

  • Security Management Server
  • Multi-Domain Security Management Server
  • Log Server
  • Multi-Domain Log Server
  • SmartEvent

Any organization running these components on a vulnerable software branch faces the same unauthenticated script execution path.

What Fixes Did Check Point Release?

Check Point published a dedicated R82.20 Security Hotfix (TAR) to resolve CVE-2026-93616. The fix was also backported into the Jumbo Hotfix Accumulator for the following branches:

  • R82.10 (Take 45)
  • R82 (Take 127)
  • R81.20 (Take 170)
  • R81.10 (Take 192)

Standard LivePatch updates do not address CVE-2026-93616. Organizations relying on LivePatch alone are still exposed and need to install the appropriate Jumbo Hotfix Accumulator or the R82.20 TAR.

What Mitigations Are Available?

For environments that cannot patch immediately, Check Point recommends two mitigations:

  • Place the Management Server behind a security gateway or firewall
  • Restrict access to TCP/19009 to trusted IP addresses only

Both steps reduce the attack surface, but they do not replace patching. The recommended path is to apply the appropriate hotfix as soon as possible.

Are There Indicators of Compromise?

Check Point released indicators of compromise alongside the patch to help security teams hunt for evidence of exploitation in their environments. Organizations using the affected management products should review the IoCs and audit their Management Server logs for signs of unauthorized access or unexpected file uploads.

A Second 9.8 Flaw Added to the KEV Catalog

CISA added CVE-2026-93616 to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, alongside a second Check Point flaw, CVE-2026-85102, which also carries a CVSS score of 9.8.

CVE-2026-85102 is an improper validation of certificate data during VPN negotiation in Check Point’s Security Gateway and Spark Firewall products. The flaw allows remote, unauthenticated attackers to bypass authentication and execute arbitrary code on the Security Gateway. Check Point originally disclosed and patched this vulnerability on September 9, 2026, with no exploitation evidence at the time. Active exploitation against Check Point Spark customers is now being observed globally.

Under BOD 26-04’s requirements, federal agencies were given three days to patch both vulnerabilities once they appeared in the KEV catalog.

What Should Organizations Do Now?

  • Identify every Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent instance in the environment
  • Install the R82.20 Security Hotfix (TAR) or the matching Jumbo Hotfix Accumulator for the installed branch
  • Verify that LivePatch alone has not been relied on as a fix for CVE-2026-93616
  • Restrict TCP/19009 access to trusted IPs as an interim step if patching will take time
  • Review the published IoCs and hunt Management Server logs for signs of compromise
  • Confirm that any Check Point Spark Firewall and Security Gateway installations have the September 9 fix for CVE-2026-85102 applied

FAQ

What is CVE-2026-93616?

CVE-2026-93616 is a critical-severity directory traversal and file upload vulnerability in Check Point Management Server with a CVSS score of 9.8. It allows unauthenticated attackers to upload and execute arbitrary scripts on the management host, and it has been exploited in the wild against a handful of customers.

Which Check Point products are affected by CVE-2026-93616?

The flaw impacts Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. It is fixed by the R82.20 Security Hotfix (TAR) and the Jumbo Hotfix Accumulator for R82.10 (Take 45), R82 (Take 127), R81.20 (Take 170), and R81.10 (Take 192). Standard LivePatch updates do not resolve it.

What should organizations do to mitigate CVE-2026-93616?

The primary action is to install the appropriate hotfix. As an interim mitigation, place the Management Server behind a security gateway or firewall and restrict access to TCP/19009 to trusted IP addresses. CISA added the vulnerability to the KEV catalog, giving federal agencies three days to patch under BOD 26-04.


This article summarizes reporting from securityweek.com.

← All Articles