Active Exploitation Alert: Critical Zero-Day (CVE-2026-93616) in Check Point Security Management Server Allowing Unauthenticated Remote Code Execution

Active Exploitation Alert: Critical Zero-Day (CVE-2026-93616) in Check Point Security Management Server Allowing Unauthenticated Remote Code Execution

Executive Summary

A critical zero-day vulnerability, CVE-2026-93616, has been identified in the Check Point Security Management Server and related products. This flaw enables unauthenticated attackers to upload and execute arbitrary scripts via the server’s web service, potentially resulting in full compromise of the management environment. Exploitation in the wild was first detected on July 23, 2026, and Check Point released a fix on September 22, 2026. The vulnerability is confirmed by CISA as actively exploited, having been added to the Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026. This advisory provides technical details, exploitation context, affected versions, mitigation guidance, and references to support your organization’s response.

Technical Information

CVE-2026-93616 is a path traversal and arbitrary file upload vulnerability affecting the web service component of the Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. The vulnerability arises from improper restriction of file and folder access, allowing attackers to traverse directories and upload malicious scripts without authentication. Once uploaded, these scripts can be executed, granting attackers the ability to run arbitrary code with the privileges of the web service process, which may lead to full system compromise.

The vulnerability is rated CVSS 9.8 (Critical) due to its remote exploitability, lack of authentication requirements, and the potential for complete takeover of the management infrastructure. Attackers exploiting this flaw can manipulate firewall policies, exfiltrate sensitive configurations, or pivot deeper into the network.

The exploitation vector is remote, targeting the exposed web service interface of the management server. Attackers do not require valid credentials, and exploitation can be performed over the internet if the service is accessible. The vulnerability impacts both on-premises and cloud deployments of the affected products.

Exploitation in the Wild

CVE-2026-93616 has been confirmed as actively exploited in targeted attacks since July 23, 2026. According to Check Point and corroborated by CISA’s KEV catalog (added September 22, 2026), exploitation has been limited in scope and highly targeted, with no evidence of mass exploitation or widespread scanning as of this report. Attackers have leveraged the vulnerability to gain initial access to management servers, but details regarding post-exploitation activities remain undisclosed by the vendor.

The attack vector involves remote access to the management server’s web service. Once exploited, attackers can upload and execute arbitrary scripts, potentially leading to unauthorized changes in firewall policies, exfiltration of sensitive data, or lateral movement within the network. There is no public proof-of-concept exploit code available at the time of writing, and exploitation details remain closely held by the vendor and trusted partners.

APT Groups using this vulnerability

As of this advisory, there is no public attribution of CVE-2026-93616 exploitation to specific Advanced Persistent Threat (APT) groups. The targeted nature of the attacks, however, suggests that sophisticated threat actors or highly motivated adversaries are likely responsible. No public breach disclosures have named affected organizations, and no threat intelligence sources have linked the exploitation to known APT campaigns. The absence of mass exploitation and the focus on high-value targets are consistent with APT tradecraft, but attribution remains speculative.

Affected Product Versions

The following Check Point product versions are confirmed as affected by CVE-2026-93616:

R82.20 (regardless of Jumbo Hotfix status), R82.10 (Jumbo Hotfix Take 44 or below), R82 (Jumbo Hotfix Take 126 or below), R81.20 (Jumbo Hotfix Take 166 or below), R81.10 (Jumbo Hotfix Take 190 or below, End of Support), R81, R80.40, R80.30, R80.20, R80.10, and R80 (all End of Support).

Organizations running any of these versions should consider themselves at risk and prioritize remediation. It is important to note that end-of-support versions are particularly vulnerable due to the lack of ongoing security updates.

Workaround and Mitigation

Immediate action is required to mitigate the risk posed by CVE-2026-93616. Organizations must apply the vendor-provided fix as detailed in Check Point support article sk1000171 (login required). Ensure your server’s release and Jumbo Hotfix take are not within the affected range.

In addition to patching, restrict access to the management server’s web service to trusted IP addresses only, leveraging network segmentation and firewall rules to minimize exposure. Administrators should review web service logs for evidence of suspicious file uploads or execution attempts and inspect management server directories for unauthorized or modified scripts. Note that installing the fix does not retroactively detect prior exploitation; proactive threat hunting is essential.

CISA’s KEV catalog mandates compliance with BOD 26-04, requiring organizations to prioritize patching of this vulnerability and follow forensics triage requirements. If mitigations are unavailable for your deployment, consider discontinuing use of the affected product until remediation is possible.

Indicators of Compromise

The following caveat applies: Indicators of Compromise (IOCs) are point-in-time and should be validated in your environment before enforcement. No public indicators of compromise were available at the time of writing.

References

The Hacker News: Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks (Sep 22, 2026), Check Point Support Article sk1000171 (Mitigation, IOCs, Fix), NVD Entry for CVE-2026-93616, CERT Santé Summary (France), The Hacker News: Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

Rescana is here for you

Rescana empowers organizations to manage third-party risk and supply chain security with our advanced TPRM platform, providing continuous monitoring, automated risk assessments, and actionable intelligence to strengthen your cybersecurity posture. We are committed to supporting your organization in navigating the evolving threat landscape. For any questions or further assistance, we are happy to help at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.