CVE-2026-93616, Check Point Security Management: pre-authentication path traversal to arbitrary script execution, exploited as a zero-day since July (CVSS 9.8)
Check Point patches a management-server zero-day it says has already been used in a handful of pinpointed attacks
Defender actions
- Apply the R82.20 Security Hotfix or the appropriate Jumbo Hotfix Accumulator to every Check Point Security Management / Multi-Domain Security Management / Log / Multi-Domain Log / SmartEvent server now; no LivePatch exists for this issue.
- Until patched, restrict TCP/19009 to trusted administrative IP ranges via Trusted Clients / implied rules on every affected server.
Analysis
Check Point discloses a pre-authentication directory-traversal and file-upload vulnerability in its Management web service that lets an unauthenticated network attacker upload a script to an arbitrary path and execute it, letting the attacker "execute a script from an arbitrary path and load an arbitrary Java class" (Check Point Support, sk1000171, 2026-09-22). It affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent; Smart-1 Cloud already carries the fix, and Security Gateway appliances and Spark Firewall are not affected. Check Point states it identified "a handful of pinpointed attacks" exploiting this as a zero-day on 2026-07-23 (Check Point Research, 2026-09-22), roughly two months before the 2026-09-22 disclosure and fix. Affected versions: R82.20 (all takes), R82.10 Jumbo Hotfix Take 44 or lower, R82 Take 126 or lower, R81.20 Take 166 or lower, R81.10 Take 190 or lower (end-of-support), and the end-of-support R80/R80.10–R80.40/R81 lines. Fixed in the R82.20 Security Hotfix, or Jumbo Hotfix Accumulator R82.10 Take 45+ / R82 Take 127+ / R81.20 Take 170+ / R81.10 Take 192+. Check Point states plainly "because of the nature of the fix, a LivePatch is not be available for this issue" (Check Point Support, sk1000171, 2026-09-22), the September LivePatch (Take 28/29) that addressed the unrelated CVE-2026-91843 flaw does not cover this vulnerability (The Hacker News, 2026-09-22). CISA added it to KEV the same day (CISA KEV, catalogue version 2026.09.22) with a 2026-09-25 remediation deadline. This is a distinct, unrelated flaw from CVE-2026-85102 (a separate Check Point Security Gateway/Spark VPN certificate-validation RCE, disclosed 2026-09-09 and now confirmed under active exploitation since 2026-09-12, see the 2026-09-10 entry's update), different components, no CVE overlap.
Detection concept, per Check Point's own two independent indicators of compromise: first, a pre-authentication login attempt whose username field is anomalously long (over 1,000 characters) in the management-process log, occurring at the same timestamp as a management-process core dump, indicates a crash consistent with exploitation attempt; second, and sufficient on its own, a resource-loading error referencing a file path containing parent-directory-reference sequences in the same log is the traversal primitive itself surfacing in application error output. Triage: the first indicator is diagnostic only as its own correlated pair; an anomalously long username alone is not; the second indicator, a traversal-pattern sequence inside the resource-loading error path, is a self-contained sign of an exploitation attempt on its own. Hardening: because no LivePatch exists, restrict network reachability to the management web service (Check Point names TCP/19009 specifically) to trusted administrative IP ranges via the platform's Trusted Clients or implied-rule mechanism, the only mitigation available short of patching.
Cited evidence
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on the Check Point Management Server. This vulnerability is exploited in the Wild. Check Point is aware of a handful of customers who have been attacked.
As of the advisory publications date, we observed a handful of pinpointed attacks on July 23, 2026.
Because of the nature of the fix, a LivePatch is not be available for this issue.
Sources4
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.