CVE-2026-93616
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute…
CISA federal remediation date Sep 25
Vulnerabilities & Exploits · Zero-Day Exploit
CSIRT Italia said attackers are actively exploiting CVE-2026-93616 in Check Point Security Management Server and related Log Server and SmartEvent components, and Check Point has issued emergency hotfixes. The flaw lets a remote, unauthenticated attacker send crafted requests that can lead to arbitrary code execution on the affected system.
That matters because these boxes are not just servers; they are the control plane for policies and logs. If an attacker lands there, they can change security policy, inspect or tamper with logs, and use that trusted position to move toward managed gateways and other connected systems.
For operators running centralized security management, the exposure is bigger than a single appliance. A compromise of the management layer can become fleet-wide control, and the reporting does not settle how far any live intrusion has already moved beyond the first box.
3 sources · 1h ago
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute…
CISA federal remediation date Sep 25
The Hacker News
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Check Point fixed a Security Management Server flaw exploited in targeted July attacks that can run scripts without login.
originalCSIRT Italia / ACN
CheckPoint: rilevato sfruttamento in rete della CVE-2026-93616
Rilevato lo sfruttamento in rete di una vulnerabilità, identificata tramite la CVE-2026-93616, presente in Check Point Management Server.
originalBleepingComputer
Check Point warns of Management Server zero-day exploited in attacks
Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts.
originalPart of the PlainSec briefing for 2026-09-22
Every edition of this story: Check Point Management Plane Under Active Exploit