Opens in a new tab

Check Point fixes critical Security Management Server zero-day exploited in the wild

  • Home
  • Blog
  • Check Point fixes critical Security Management Server zero-day exploited in the wild
Check Point security management server breach sealed by a glowing patch

What happened

A path traversal flaw in Check Point’s Security Management Server is now being exploited in real attacks, and the company has shipped an emergency fix. Tracked as CVE-2026-93616, the vulnerability lets unauthenticated attackers upload and run arbitrary scripts on vulnerable management servers, and exploitation began on September 12 against Spark customers.

Check Point released the fix in the R82.20 Security Hotfix and confirmed that a small number of customers have already been hit. The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have been asking software vendors to eliminate this class of weakness since May 2024, calling path traversal bugs unforgivable.

What the vulnerability does

Security Management Server is the central control plane for enterprise Check Point deployments. It stores and manages security policies, processes administrator changes, and collects system logs across the network. A path traversal flaw in that system gives an unauthenticated attacker a direct path to upload scripts and execute them, and Check Point rates the attack low complexity. Once an attacker lands on the management server, they sit on the system used to push policy to the rest of the environment.

Which products are affected

  • Security Management Server
  • Multi-Domain Security Management Server
  • Log Server
  • Multi-Domain Log Server
  • SmartEvent

What to do right now

Apply the R82.20 Security Hotfix as soon as the change window allows. For environments that cannot patch immediately, Check Point published temporary mitigation steps in its security advisory, including hardening vulnerable systems by placing them behind a firewall and limiting access to trusted IP addresses through the Manage Settings, Permissions, Administrators, Trusted Clients section in the SmartConsole dashboard. Security teams should also review the indicators of compromise in the advisory and hunt their networks for any sign of successful exploitation.

How this fits a wider pattern at Check Point

This is the latest in a string of actively exploited flaws across Check Point’s product line. Two years ago, CISA flagged CVE-2024-24919 in Quantum Security Gateways as exploited by ransomware gangs, and Orange Cyberdefense CERT linked those attacks to NailaoLocker ransomware. A Qilin ransomware affiliate has been exploiting authentication bypass CVE-2026-50751 since June. A second authentication bypass, CVE-2026-16232, has been exploited since at least July to log into SmartConsole admin panels with administrator privileges. Two weeks before this latest advisory, the Dutch National Cyber Security Centre (NCSC-NL) urged organizations to urgently patch two critical Check Point VPN flaws, CVE-2026-85102 and CVE-2026-85103, expecting exploitation to follow. Check Point also recently shipped security updates for CVE-2026-16232 in the Security Management Server and Security Gateways login process, which lets attackers run code as root on management systems. CVE-2026-16232 is not yet flagged as actively exploited, but admins can spot attempts by watching for the alert text “Administrator failed to log in: Username too long” in the Audit and Admin login logs.

Why management plane flaws matter most

Flaws in the management plane are the most consequential bugs a vendor can ship. The management server is the system administrators use to write and push policy, see logs, and manage every gateway downstream. An attacker who lands on the management server does not need a separate exploit for each gateway; they can change policy, disable protections, or read logs that show the rest of the environment. That is why CISA, the FBI, and national cyber centers in multiple countries keep pushing vendors to remove path traversal and authentication bypass flaws before release, and why security teams should treat any unauthenticated flaw on a management product as an emergency patch even when no exploitation is public yet.

FAQ

What is CVE-2026-93616?

CVE-2026-93616 is a critical path traversal vulnerability in Check Point Security Management Server that lets unauthenticated attackers upload and execute arbitrary scripts. Check Point confirmed it is being exploited in the wild.

Which Check Point products are affected by CVE-2026-93616?

Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.

How should organizations respond?

Apply the R82.20 Security Hotfix as soon as possible. Where patching must wait, restrict access to the management server behind a firewall and to trusted IP addresses through the SmartConsole Trusted Clients settings, and audit networks using the indicators of compromise Check Point shared in its advisory.


This article summarizes reporting from bleepingcomputer.com.

← All Articles