VYPR
advisoryPublished Sep 22, 2026· 2 sources

Check Point Management Server Zero-Day Exploited in Targeted Attacks

Check Point is warning of active exploitation of a critical zero-day vulnerability, CVE-2026-93616, in its Security Management Server, allowing unauthenticated remote code execution.

Check Point has issued an urgent warning to its customers regarding the active exploitation of a critical zero-day vulnerability within its Security Management Server infrastructure. The flaw, identified as CVE-2026-93616, carries a severe CVSS score of 9.8 and permits unauthenticated remote attackers to upload and execute arbitrary scripts on an exposed Management Server.

Check Point has confirmed observing a limited number of targeted customer attacks that predate the availability of a fix, underscoring the zero-day nature of this threat. The vulnerability is a sophisticated combination of directory traversal and an unsafe file upload mechanism within the Check Point Management web service. Attackers can leverage this by manipulating file paths to trick the service into executing scripts from arbitrary locations and loading unauthorized Java classes without requiring any form of authentication.

Successful exploitation grants an external adversary the ability to run their own code on a highly privileged system. The Security Management Server is a critical component responsible for administering security policies, managing network devices, and collecting vital operational data. Compromising this server provides attackers with significant control over an organization's security posture.

The observed exploitation activity occurred on July 23, 2026, well before Check Point could release a security update. While the vendor has not publicly attributed these intrusions or detailed the attackers' specific objectives or payloads, the limited scope suggests a targeted campaign rather than a widespread automated attack.

A wide range of Check Point products are affected, including Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Vulnerable software releases include R82.20, R82.10 (Jumbo Hotfix Take 44 and earlier), R82 (Take 126 and earlier), R81.20 (Take 166 and earlier), and the end-of-support R81.10 (Take 190 and earlier). All R80, R80.10, R80.20, R80.30, R80.40, and R81 versions are also susceptible.

Check Point has released emergency fixes for the vulnerability. Affected administrators are urged to apply the R82.20 Security Hotfix or upgrade to a fixed Jumbo Hotfix Accumulator immediately. Specific patch levels include R82.10 Take 45, R82 Take 127, R81.20 Take 170, and R81.10 Take 192 or later. Smart-1 Cloud is not vulnerable as the fix has already been applied, and Check Point Firewall Appliances and Spark Firewall are unaffected.

As a temporary mitigation until patching is complete, Check Point recommends ensuring management servers are protected behind a Security Gateway or Check Point firewall and restricting access to TCP port 19009 to trusted IP addresses only. Trusted clients within SmartConsole should also be limited to trusted internal addresses.

Check Point's advisory provides specific commands for incident responders to hunt for signs of exploitation, including searching logs for unusually long usernames and correlating them with core dumps, as well as looking for specific error messages related to the ReflectionUtils service. Organizations that identify suspicious activity should preserve evidence, isolate affected systems where possible, and contact Check Point Support for assistance.

This new report details that the exploitation of CVE-2026-93616 occurred on July 23rd in a handful of targeted attacks, and further specifies the vulnerability as a path traversal bug within the management server's web service that allows attackers to upload and execute scripts. Additionally, the article mentions separate, ongoing exploitation attempts against a different Check Point VPN flaw (CVE-2026-85102) targeting Spark firewalls since September 12th.

Synthesized by Vypr AI
Check Point Management Server Zero-Day Exploited in Targeted Attacks · VYPR