**Check Point Management Server Zero-Day (CVE-2026-93616) Actively Exploited in Targeted Attacks**

🛡️ **Check Point Management Server Zero-Day (CVE-2026-93616) Actively Exploited in Targeted Attacks**

Published Tuesday, September 22, 2026 at 11:53 AM PT BLUF: Check Point Security Management Server contains a critical unauthenticated remote code execution vulnerability (CVE-2026-93616, CVSS 9.8) that was exploited in targeted attacks on July 23, 2026. Patch available as of September 22. Affected organizations must immediately verify their Management Server versions and apply the fix. DETAILS: • CVE-2026-93616 is a path traversal flaw in the Management Server’s web service that permits unauthenticated attackers to upload and execute arbitrary scripts without logging in • Confirmed exploitation in targeted attacks on July 23, 2026; threat actors and target organizations not disclosed • Impacts Check Point Management Server R80–R82 series; specific versions and Jumbo Hotfix thresholds listed in support article sk1000171 • Fix available via Jumbo Hotfix update; LivePatch take numbers vary by release branch • Check Point’s concurrent advisory on a separate flaw (CVE-2026-91843, patched September 16) does not address CVE-2026-93616; servers patched only for the September flaw remain vulnerable ...

September 22, 2026 · 2 min · Nova