TL;DR
Check Point warned of an actively exploited Check Point Management vulnerability. Attackers use CVE-2026-93616 to run unauthorized code on affected servers. Diagram showing the exploited Check Point Management vulnerabilityOrganizations must restrict network access immediately to prevent compromise.
- CVE: CVE-2026-93616
- CVSS: 9.8 (Critical · CVSSv3)
- Product: checkpoint Quantum Security Management
- Affected: R82.20 with no Jumbo Hotfix, R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, R81.10 (EOS) with Jumbo Hotfix Take 190 or below, R81 (EOS) (+5 more)
- Impact: Directory Traversal and File upload allows execution of arbitrary script on the Management Server
- Status: Exploited in the wild
- Action: See vendor advisory
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy It Matters
Enterprise networks rely on management servers to coordinate security policies. A breach here grants attackers widespread network control. Security analysts confirm this flaw is exploited in the wild. Check Point stated, “Check Point is aware of a handful of customers who have been attacked.” Vulnerability details have been publicly disclosed. However, researchers have not confirmed a public proof-of-concept exploit. Install estimates are unavailable, but these products protect thousands of corporate networks globally.
How The Attack Works
The vulnerability combines directory traversal and unrestricted file uploads. An unauthenticated attacker connects to an exposed server via TCP port 19009. The attacker then uploads a malicious payload. The directory traversal flaw helps bypass restricted upload folders. This sequence lets the attacker execute arbitrary scripts directly via this Check Point Management vulnerability.
Affected Versions
The vulnerability impacts Security Management Server and Multi-Domain Security Management Server. It also affects Log Server, Multi-Domain Log Server, and SmartEvent. Affected software includes versions R82.20, R82.10, R82, R81.20, and R81.10. Older End-of-Support versions from R80 through R81 are also vulnerable. Smart-1 Cloud and Check Point Firewall Appliances remain unaffected.
Patch Or Mitigation Steps
Check Point has not released a final patch for all versions yet. LivePatch Take 28 and 29 do not fix this issue. Administrators must limit access to management servers behind a security gateway. Ensure that access to TCP port 19009 is restricted to trusted IP addresses only. Review the official Check Point advisory for detailed configuration instructions.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!