Check Point has issued a warning to its users regarding a critical zero-day vulnerability impacting its Security Management systems. This flaw, identified as CVE-2026-93616, has been given a high severity rating with a CVSS score of 9.8. It allows unauthenticated remote attackers to upload and execute arbitrary scripts on vulnerable Management Servers.
Details of the Exploitation
The company has detected several targeted attacks exploiting this vulnerability and has rolled out urgent patches. The security gap arises from a combination of directory traversal and unsafe file-upload practices within the Check Point Management web service. Attackers can manipulate file paths to execute scripts from arbitrary locations, leading to unauthorized execution of code with high privileges.
Such exploitation gives adversaries the ability to control systems responsible for enforcing security policies and collecting data. Although Check Point describes the attacks as restricted and specific, they occurred before public disclosure, classifying it as a zero-day vulnerability. The initial attacks took place on July 23, 2026.
Affected Systems and Fixes
The vulnerability impacts several products including Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Vulnerable versions are R82.20, R82.10 Jumbo Hotfix Take 44 and earlier, R82 Take 126 and earlier, R81.20 Take 166 and earlier, and end-of-support R81.10 Take 190 and earlier. All R80, R80.10, R80.20, R80.30, R80.40, and R81 versions are also affected.
Smart-1 Cloud remains secure as the fix has been applied, and Check Point Firewall Appliances and Spark Firewalls are not affected. However, administrators should not rely on LivePatch as it does not address CVE-2026-93616. Immediate installation of the R82.20 Security Hotfix or moving to a fixed Jumbo Hotfix Accumulator is recommended.
Recommendations and Response
Until patches are implemented, it is crucial to keep management servers behind a Security Gateway or Check Point firewall while restricting TCP port 19009 to trusted IP addresses. Trusted Clients should only include verified internal addresses in SmartConsole.
Check Point advises incident responders to examine all affected servers, not just those exposed to the internet. Experts should run commands in Expert mode to identify anomalies in cpm.elg logs and correlate them with FWM or MDS core dumps. Any signs of exploitation should prompt immediate forensic investigation.
Given the potential for a management server compromise to give attackers control over critical administrative functions, applying the hotfix should be a top priority. Suspicious logs should be preserved, and affected servers isolated for further assessment. Check Point Support should be contacted for assistance, and the company’s latest advisory, updated on September 22, 2026, should be monitored for new information.
