Pierluigi Paganini
September 22, 2026

Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. The security firm bug is already being exploited. Attackers can abuse the flaw without logging in to upload malicious scripts and execute them on vulnerable servers.
Because the Management Server controls security policies, admin activity and system logs across Check Point deployments, a compromise could have a wider impact on an enterprise network.
The vulnerability affects more than Check Point’s main Security Management Server. The impacted products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Check Point fixed the issue in the R82.20 Security Hotfix and is urging customers to act quickly.
The company revealed the flaw “is exploited in the wild” and that it is aware of a handful of customers who have already been attacked. The actual number of victims could be higher, since some compromises may go undetected or never be reported to Check Point.
The company has also published indicators of compromise (IOCs) in its advisory, giving security teams a way to check their systems and logs for signs of an attack.
If the hotfix cannot be installed immediately, the cybersecurity firm recommends placing the vulnerable system behind a firewall and allowing access only from trusted IP addresses. This can be configured through Manage & Settings → Permissions & Administrators → Trusted Clients in SmartConsole. It is only a temporary measure, however.
Two weeks ago, the Dutch National Cyber Security Centre warned of two critical Check Point VPN flaws, tracked as CVE-2026-85102 and CVE-2026-85103, saying it expected exploitation attempts to start soon. In July, Check Point patched yet another critical authentication bypass, tracked as CVE-2026-16232, affecting Security Management and Multi-Domain Management (MDSM).
The vulnerability, which is under active exploitation, allows unauthenticated remote attackers to obtain a SmartConsole login token and gain full administrative access.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, BigDiskBuster)