Published Tuesday, September 22, 2026 at 11:53 AM PT

<strong>Check Point Management Server Zero-Day (CVE-2026-93616) Actively Exploited in Targeted Attacks</strong>

BLUF: Check Point Security Management Server contains a critical unauthenticated remote code execution vulnerability (CVE-2026-93616, CVSS 9.8) that was exploited in targeted attacks on July 23, 2026. Patch available as of September 22. Affected organizations must immediately verify their Management Server versions and apply the fix.

DETAILS: • CVE-2026-93616 is a path traversal flaw in the Management Server’s web service that permits unauthenticated attackers to upload and execute arbitrary scripts without logging in • Confirmed exploitation in targeted attacks on July 23, 2026; threat actors and target organizations not disclosed • Impacts Check Point Management Server R80–R82 series; specific versions and Jumbo Hotfix thresholds listed in support article sk1000171 • Fix available via Jumbo Hotfix update; LivePatch take numbers vary by release branch • Check Point’s concurrent advisory on a separate flaw (CVE-2026-91843, patched September 16) does not address CVE-2026-93616; servers patched only for the September flaw remain vulnerable

IMPACT: Organizations running unpatched Check Point Management Server are at risk of complete compromise. A remote, unauthenticated attacker can execute code on the device controlling firewall policies across the entire managed gateway fleet. No target disclosure; scope and payload of July attacks undisclosed. Successful exploitation cannot be detected retrospectively via logs or system state.

RECOMMENDED ACTIONS:

  1. Identify all Check Point Management Server instances and cross-reference against affected versions/hotfix levels (R82.20 without Jumbo Hotfix; R82.10 up to Take 44; R82 up to Take 126; R81.20 up to Take 166; R81.10 up to Take 190; R80 series all versions)
  2. Retrieve fixed builds and deployment guidance from Check Point support article sk1000171
  3. Apply patch immediately to all affected systems
  4. Review hunting indicators in sk1000171 for evidence of pre-patch exploitation
  5. Escalate to incident response if compromise cannot be ruled out

SECONDARY ISSUE: CVE-2026-85102 (VPN certificate validation flaw in Spark firewalls) has been under active exploitation since September 12, 2026. Fix available since September 9. Consult support article sk1000117.

SOURCES: BleepingComputer / The Hacker News (Swati Khandelwal, Sep 22, 2026)


Recent high-severity events at publish time:

Recent high-severity events