Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-93616: Check Point servers let attackers upload and run scripts
CVE-2026-93616 · published 19 days ago · actively exploited
Summary
The Security Management Server, Multi‑Domain Security Management Server, Log Server, Multi‑Domain Log Server, and SmartEvent can be tricked into accepting files from anyone on the network. An attacker could place malicious code on these systems and have it executed, potentially compromising your environment. Install the latest security updates from Check Point as soon as possible to close the gap.
What to do
- Update checkpoint multi-domain_security_management to version r81.10 or later.
- Update checkpoint quantum_security_management to version r81.10 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| checkpoint | quantum security management | R82.20 with no Jumbo Hotfix |
| check point | multiple products | All versions |
| checkpoint | multi-domain_security_management |
>= r80, < r81.10 r81.10 r81.20 r82 r82.10 r82.20 cpe:2.3:a:checkpoint:multi-domain_security_management:*:*:*:*:*:*:*:* |
| checkpoint | quantum_security_management |
>= r80, < r81.10 r81.10 r81.20 r82 r82.10 r82.20 cpe:2.3:a:checkpoint:quantum_security_management:*:*:*:*:*:*:*:* |
Original advisory text
Check Point Multiple Products Path Traversal Vulnerability
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.
References
- https://support.checkpoint.com/results/sk/sk1000171 Mitigation Patch Vendor Advisory
- https://blog.checkpoint.com/security/security-advisory-action-required-active-ex... Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-... US Government Resource
Internet-facing
3 days
and check for signs of compromise
Internal
3 days
and check for signs of compromise
- Known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
20%
chance of attack within 30 days
Type
CWE-22Path Traversal
Timeline
Published22 Sep 2026
Updated9 Oct 2026
First seen22 Sep 2026
Track software like this
Free during beta