---
schema: 1
kind: vulnerability
title: "CVE-2026-93616 — Check Point Security Management: pre-authentication path traversal to arbitrary script execution, exploited as a zero-day since July (CVSS 9.8)"
headline: "Check Point patches a management-server zero-day it says has already been used in a handful of pinpointed attacks"
summary: >
  An unauthenticated attacker can upload and execute an arbitrary script on
  Check Point Security Management Server, Multi-Domain Security Management
  Server, Log Server, Multi-Domain Log Server and SmartEvent via a
  directory-traversal and file-upload flaw. Check Point identified pinpointed
  exploitation on 2026-07-23, roughly two months before the 2026-09-22 fix;
  no LivePatch exists, only a hotfix or Jumbo Hotfix Accumulator.
discovered_at: "2026-09-23T04:40:00Z"
updated_at: null
event_date: "2026-09-22"
run_id: 2026-09-23T0405Z-intel
priority: critical
immediate_action:
  title: "Patch every Check Point Security Management / Multi-Domain / Log / SmartEvent server now — no LivePatch exists"
  action: >
    Check Point confirms this pre-authentication path-traversal flaw has
    already been exploited as a zero-day against a handful of customers
    since 2026-07-23. Apply the R82.20 Security Hotfix or the appropriate
    Jumbo Hotfix Accumulator (R82.10 Take 45+, R82 Take 127+, R81.20 Take
    170+, R81.10 Take 192+) immediately — the September LivePatch does not
    cover this issue. Until patched, restrict TCP/19009 on every affected
    server to trusted administrative IP ranges via Trusted Clients / implied
    rules, and review management-process logs for the correlated crash
    pattern described below.
tags: [vulnerabilities, rce, pre-auth, actively-exploited, zero-day, cisa-kev, no-patch]
regions: [global]
sectors: [public-sector]
entities: ["product:check-point-security-management-server", "product:check-point-multi-domain-security-management-server", "product:check-point-log-server", "product:check-point-multi-domain-log-server", "product:check-point-smartevent"]
techniques: [T1190, T1505.003]
affected_products: ["Check Point Security Management Server", "Check Point Multi-Domain Security Management Server", "Check Point Log Server", "Check Point Multi-Domain Log Server", "Check Point SmartEvent"]
cves:
  - id: CVE-2026-93616
    cvss: "9.8"
    epss: null
    type: path-traversal
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, no-patch]
    affected: "R82.20 (all takes); R82.10 Jumbo Hotfix Take 44 or lower; R82 Take 126 or lower; R81.20 Take 166 or lower; R81.10 Take 190 or lower (EoS); R80/R80.10–R80.40/R81 (all EoS)"
    fixed: "R82.20 Security Hotfix; Jumbo Hotfix Accumulator R82.10 Take 45+ / R82 Take 127+ / R81.20 Take 170+ / R81.10 Take 192+ — no LivePatch available"
sources:
  - url: "https://support.checkpoint.com/results/sk/sk1000171/"
    publisher: "Check Point Support (sk1000171)"
    date: "2026-09-22"
    role: primary
  - url: "https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/"
    publisher: "Check Point Research (blog)"
    date: "2026-09-22"
    role: primary
  - url: "https://thehackernews.com/2026/09/check-point-warns-of-management-server.html"
    publisher: "The Hacker News"
    date: "2026-09-22"
    role: corroborating
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA KEV"
    date: "2026-09-22"
    role: corroborating
closed_sources: []
evidence:
  - quote: "A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on the Check Point Management Server. This vulnerability is exploited in the Wild. Check Point is aware of a handful of customers who have been attacked."
    publisher: "Check Point Support (sk1000171)"
    source_url: "https://support.checkpoint.com/results/sk/sk1000171/"
  - quote: "As of the advisory publications date, we observed a handful of pinpointed attacks on July 23, 2026."
    publisher: "Check Point Research (blog)"
    source_url: "https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/"
  - quote: "Because of the nature of the fix, a LivePatch is not be available for this issue."
    publisher: "Check Point Support (sk1000171)"
    source_url: "https://support.checkpoint.com/results/sk/sk1000171/"
verification: multi-source
sourcing_note: null
confidence: high
references: ["2026-09-10/checkpoint-quantum-vpn-cert-preauth-rce-cvss98"]
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - "Apply the R82.20 Security Hotfix or the appropriate Jumbo Hotfix Accumulator to every Check Point Security Management / Multi-Domain Security Management / Log / Multi-Domain Log / SmartEvent server now — no LivePatch exists for this issue."
  - "Until patched, restrict TCP/19009 to trusted administrative IP ranges via Trusted Clients / implied rules on every affected server."
updates: []
migrated_from: null
---

Check Point discloses a pre-authentication directory-traversal and file-upload vulnerability in its Management web service that lets an unauthenticated network attacker upload a script to an arbitrary path and execute it, letting the attacker "execute a script from an arbitrary path and load an arbitrary Java class" ([Check Point Support, sk1000171, 2026-09-22](https://support.checkpoint.com/results/sk/sk1000171/)). It affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent — Smart-1 Cloud already carries the fix, and Security Gateway appliances and Spark Firewall are not affected. Check Point states it identified "a handful of pinpointed attacks" exploiting this as a zero-day on 2026-07-23 ([Check Point Research, 2026-09-22](https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/)) — roughly two months before the 2026-09-22 disclosure and fix. Affected versions: R82.20 (all takes), R82.10 Jumbo Hotfix Take 44 or lower, R82 Take 126 or lower, R81.20 Take 166 or lower, R81.10 Take 190 or lower (end-of-support), and the end-of-support R80/R80.10–R80.40/R81 lines. Fixed in the R82.20 Security Hotfix, or Jumbo Hotfix Accumulator R82.10 Take 45+ / R82 Take 127+ / R81.20 Take 170+ / R81.10 Take 192+. Check Point states plainly "because of the nature of the fix, a LivePatch is not be available for this issue" ([Check Point Support, sk1000171, 2026-09-22](https://support.checkpoint.com/results/sk/sk1000171/)) — the September LivePatch (Take 28/29) that addressed the unrelated CVE-2026-91843 flaw does not cover this vulnerability ([The Hacker News, 2026-09-22](https://thehackernews.com/2026/09/check-point-warns-of-management-server.html)). CISA added it to KEV the same day ([CISA KEV, catalogue version 2026.09.22](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)) with a 2026-09-25 remediation deadline. This is a distinct, unrelated flaw from CVE-2026-85102 (a separate Check Point Security Gateway/Spark VPN certificate-validation RCE, disclosed 2026-09-09 and now confirmed under active exploitation since 2026-09-12 — see the 2026-09-10 entry's update) — different components, no CVE overlap.

Detection concept, per Check Point's own two independent indicators of compromise: first, a pre-authentication login attempt whose username field is anomalously long (over 1,000 characters) in the management-process log, occurring at the same timestamp as a management-process core dump, indicates a crash consistent with exploitation attempt; second, and sufficient on its own, a resource-loading error referencing a file path containing parent-directory-reference sequences in the same log is the traversal primitive itself surfacing in application error output. **Triage:** the first indicator is diagnostic only as its own correlated pair — an anomalously long username alone is not; the second indicator, a traversal-pattern sequence inside the resource-loading error path, is a self-contained sign of an exploitation attempt on its own. Hardening: because no LivePatch exists, restrict network reachability to the management web service (Check Point names TCP/19009 specifically) to trusted administrative IP ranges via the platform's Trusted Clients or implied-rule mechanism — the only mitigation available short of patching.

**Defender takeaway:** treat any affected server that was internet-reachable on TCP/19009 before 2026-09-22 as a potential compromise-assessment target, not just a patch target — Check Point's own two-month exploitation timeline means an unpatched, exposed server could have been silently compromised since July.
