Check Point Patches Management Server Zero-Day
CVE-2026-93616: CVSS 9.8 Check Point Management Server flaw allows unauth script execution via path traversal. Added to CISA KEV with a Sept. 25 deadline.

Check Point has issued emergency hotfixes for CVE-2026-93616, a CVSS 9.8 directory traversal and file upload vulnerability in its Security Management Server that allows an unauthenticated attacker to upload and execute arbitrary scripts. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 22, with a September 25 remediation deadline for federal agencies under BOD 26-04.
The exploitation that triggered the KEV listing happened months before today’s public disclosure. According to The Hacker News, attackers used CVE-2026-93616 in a handful of targeted attacks on July 23. More than two months passed between those incidents and the CVE’s public CISA listing.
The vulnerability
CVE-2026-93616 is a path traversal combined with an unauthenticated file upload in Check Point’s management layer. The combination gives an attacker a path to write and then execute arbitrary scripts on the server with no credentials required. The flaw affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
Management servers are not always directly internet-facing, but they often sit in positions reachable from compromised internal hosts or VPN endpoints. The July 23 exploitation was described as targeted, not mass exploitation. Now that the flaw is public and on the KEV list, that may not hold.
The Check Point advisory and NVD record have full version details; BleepingComputer and SecurityWeek confirmed emergency hotfixes are available.
What to do
Apply the Check Point emergency hotfixes. The advisory contains remediation steps by product version. Federal agencies under BOD 26-04 have until September 25; that deadline also serves as a useful urgency signal for commercial operators running any of the five affected products.
Context
CVE-2026-93616 is the third Check Point management or VPN component to see active exploitation in 2026. Earlier this month, CVE-2026-91843 delivered RCE on the Management Server via a different code path. Before that, two CVSS 9.8 VPN RCE flaws were patched in early September, and the Dutch NCSC warned of imminent exploitation shortly after.
The broader pattern is consistent enough to treat Check Point’s network security stack as an active patching priority, regardless of whether any single CVE maps to a given deployment’s configuration.
September 25 is the federal floor. For Check Point customers, it is worth treating it as the ceiling.
- [ CRITICAL ]CVE-2026-93616Check Point Multiple Products Path Traversal Vulnerability
Found this useful? Share it.


