// 1 CRITICAL · 5 ZERO-DAY · 7 CVE · 9 EXPLOIT · 1 ADVISORY IN THE LAST 24H
Check Point has fixed the zero-day vulnerability CVE-2026-93616 in Security Management Server, actively exploited in July 2026. The CVSS 9.8 flaw allows unauthenticated remote code execution.

Check Point released the fix for CVE-2026-93616 on September 22, 2026, a critical vulnerability with a CVSS 9.8 score in Security Management Server that was already exploited in targeted attacks on July 23, 2026. The flaw allows a remote, unauthenticated attacker to upload and execute arbitrary scripts through a combination of path traversal and file upload, compromising the core of security policy management infrastructures.

Key Takeaways
  • CVE-2026-93616 carries a CVSS 9.8 score and is actively exploited: Check Point confirms "a handful of customers" compromised on July 23, 2026
  • The mechanism combines directory traversal and file upload in the Management Server web service to execute scripts without authentication
  • The fix requires R82.20 Security Hotfix: Check Point LivePatch Take 28/29 does not resolve the vulnerability
  • End-of-service versions R81.10 Jumbo Hotfix Take 190 or lower, R80-R81 remain exposed without an official patch

The Mechanism: How the Management Server Failed

The Security Management Server is the operational brain of Check Point infrastructures: it hosts firewall policies, security logs, network configurations, and events correlated by SmartEvent. Its compromise is not a peripheral incident but a structural failure that exposes the entire defense architecture.

According to Check Point's official support article sk1000171, the vulnerability resides in a missing restriction of filesystem path access in the Management Server web service. An attacker can exploit the path traversal to place scripts in executable directories, triggering them without the need for credentials.

"A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on the Check Point Management Server."

— Check Point Software, sk1000171

Affected products span the entire management stack: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Affected versions range from the R80-R81 family (all end-of-service) through R81.20, R82, R82.10, and pre-patch R82.20. Smart-1 Cloud is not vulnerable due to a fix already applied, while firewall appliances and Spark are excluded from the scope of the flaw.

The July Attack: What We Know and What We Don't

The Hacker News first reported that the attacks occurred on July 23, 2026, describing them as "a handful of targeted attacks" against a limited number of customers. Check Point confirmed this reconstruction: "This vulnerability is exploited in the Wild. Check Point is aware of a handful of customers who have been attacked" (Check Point, sk1000171).

The identity of the threat actors has not been determined. The dossier does not specify sectors, geographies, or attacker motivations. No infrastructure overlaps link the July 2026 operators to known campaigns. Post-exploitation actions are not documented in available sources.

BleepingComputer rounded out the picture, confirming the in-the-wild exploitation and adding historical context on other Check Point vulnerabilities in 2026, signaling a pattern of growing interest in the platform.

Indicators of Compromise and the False Comfort of LivePatch

Check Point published specific grep commands to detect exploitation attempts. The patterns include abnormally long usernames with repetitive sequences and verification of FWM and MDS process core dumps. These IoCs allow discrimination between legitimate activity and exploitation, though their absence does not guarantee the system is intact.

An element of particular operational relevance: Check Point LivePatch Take 28/29 does not resolve CVE-2026-93616. Organizations relying solely on this channel remain vulnerable. The fix explicitly requires the application of R82.20 Security Hotfix, with implications for maintenance window planning on systems that in many environments operate with high continuity.

The severity of the CVSS 9.8 reflects the combination of unauthenticated network access, low attack complexity, and total impact on confidentiality, integrity, and availability. This is not a defect that requires special conditions: the attacker only needs to reach the vulnerable service.

Immediate Actions

Priority actions derive directly from the Check Point advisory:

  • Apply R82.20 Security Hotfix on all instances of Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent in affected versions
  • Verify through the grep commands published by Check Point the presence of login patterns with abnormally long usernames and FWM/MDS core dumps in systems exposed during the July-September 2026 period
  • Do not consider LivePatch Take 28/29 sufficient: the mechanism does not cover this vulnerability
  • Plan upgrades for end-of-service versions R80-R81 and R81.10 Jumbo Hotfix Take 190 or lower, for which no official patch exists
  • Confirm that Smart-1 Cloud is already protected and that firewall appliances and Spark require no action

Why This Matters

The Security Management Server is not a secondary component: it is the consolidation point for the security decisions of the entire organization. Its compromise through a vulnerability exploitable without authentication and with low technical complexity represents a systemic risk that transcends the single system.

The fact that LivePatch Take 28/29 does not resolve the problem introduces a significant operational asymmetry. Many organizations have structured their patching processes around this mechanism to minimize downtime: the discovery that it does not cover CVE-2026-93616 forces a revision of maintenance procedures.

Check Point reacted promptly between the July attack and the September patch, but the two-month gap left customers exposed who were not covered by alternative countermeasures. The confirmation of targeted exploitation, albeit on a limited scale, signals that the vulnerability was assessed as instrumental by operators capable of identifying and striking specific targets.

For organizations managing Check Point infrastructures, verifying exposure and applying the R82.20 Security Hotfix are not deferrable actions. The CVSS 9.8 and confirmation of attacks in the wild remove any margin for procrastination.

Information has been verified against cited sources and updated at the time of publication.

Sources


Sources and references
  1. thehackernews.com
  2. bleepingcomputer.com
  3. radar.offseq.com
  4. cve.org
  5. nvd.nist.gov
  6. support.checkpoint.com
  7. securityweek.com
  8. research.checkpoint.com