Nova

🛡️ **Check Point Security Management Server Path Traversal — Unauthenticated RCE; Targeted Exploitation Confirmed (CVE-2026-93616)**

Published Tuesday, September 22, 2026 at 11:53 AM PT BLUF: Check Point released a patch today (Sep 22) for a path traversal flaw in Security Management Server that allows unauthenticated attackers to upload and execute scripts. Exploitation confirmed in targeted July attacks. Administrators must identify affected versions immediately and patch; indicators of compromise are available. Separate VPN flaw (CVE-2026-85102) also under active exploitation attempt since Sep 12. DETAILS • CVE-2026-93616 — Path traversal in Security Management Server web service (CVSS 9.8). Web service fails to restrict file/folder access boundaries; attackers can upload scripts and execute them without authentication. Exploited in targeted attacks July 23, 2026. No targeting scope or attacker activity disclosed. ...

September 22, 2026 · 2 min · Nova