Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-93616NVD

Vulnerability Summary

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
Severity Level
CRITICAL(9.8)
Published Date
Sep 22, 2026
Last Modified
Sep 22, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.
CVSS v3.1 Base Metrics — Score 9.8 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • checkpoint Quantum Security Management >= R82.20 with no Jumbo Hotfix
  • checkpoint Quantum Security Management >= R82.10 with Jumbo Hotfix Take 44 or below
  • checkpoint Quantum Security Management >= R82 with Jumbo Hotfix Take 126 or below
  • checkpoint Quantum Security Management >= R81.20 with Jumbo Hotfix Take 166 or below
  • checkpoint Quantum Security Management >= R81.10 (EOS) with Jumbo Hotfix Take 190 or below
  • checkpoint Quantum Security Management >= R81 (EOS)
  • checkpoint Quantum Security Management >= R80.40 (EOS)
  • checkpoint Quantum Security Management >= R80.30 (EOS)
  • checkpoint Quantum Security Management >= R80.20 (EOS)
  • checkpoint Quantum Security Management >= R80.10 (EOS)
  • checkpoint Quantum Security Management >= R80 (EOS)
Patched Versions
Not provided by cveorg for this CVE.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.