Check Point patches actively exploited zero-day in Security Management Server
Check Point Software has issued emergency hotfixes for CVE-2026-93616, a critical path traversal vulnerability in its Security Management Server that lets unauthenticated attackers upload and run arbitrary scripts. The company confirmed the flaw is being actively exploited, with a handful of customers already compromised, and released a fix in R82.20 Security Hotfix covering Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
GoKawiil's interpretation of the reporting above, not reported fact.
Because the Security Management Server centrally controls security policies and logs across enterprise networks, compromising it could give attackers broad access to an organization's entire security infrastructure. The flaw's low complexity and unauthenticated exploitation make it especially dangerous, echoing CISA and FBI warnings that path traversal bugs remain an inexcusable, recurring class of vulnerability in enterprise software.
- CVE-2026-93616 allows unauthenticated attackers to upload and execute scripts on Check Point servers.
- Check Point confirmed active exploitation affecting a small number of customers.
- Organizations unable to patch immediately should restrict access via Trusted Clients settings in SmartConsole.
Source: bleepingcomputer.com, 2026-09-22
Published there as: “Check Point warns of Management Server zero-day exploited in attacks”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.