Vulnerabilities · 25m ago

Check Point Management Plane Under Active Exploit

CSIRT Italia said attackers are actively exploiting CVE-2026-93616 in Check Point Security Management Server and related Log Server and SmartEvent components, and Check Point has issued emergency hotfixes. The flaw lets a remote, unauthenticated attacker send crafted requests that can lead to arbitrary code execution on the affected system.

That matters because these boxes are not just servers; they are the control plane for policies and logs. If an attacker lands there, they can change security policy, inspect or tamper with logs, and use that trusted position to move toward managed gateways and other connected systems.

For operators running centralized security management, the exposure is bigger than a single appliance. A compromise of the management layer can become fleet-wide control, and the reporting does not settle how far any live intrusion has already moved beyond the first box.

CVE-2026-93616

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: a directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute…

CISA federal remediation date Sep 25

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-09-22

Editions

Related stories