Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-93616: Check Point servers let attackers upload and run scripts

CVE-2026-93616 · published 19 days ago · actively exploited
Summary

The Security Management Server, Multi‑Domain Security Management Server, Log Server, Multi‑Domain Log Server, and SmartEvent can be tricked into accepting files from anyone on the network. An attacker could place malicious code on these systems and have it executed, potentially compromising your environment. Install the latest security updates from Check Point as soon as possible to close the gap.

What to do
  • Update checkpoint multi-domain_security_management to version r81.10 or later.
  • Update checkpoint quantum_security_management to version r81.10 or later.
Affected software
VendorProductAffected versions
checkpoint quantum security management R82.20 with no Jumbo Hotfix
check point multiple products All versions
checkpoint multi-domain_security_management >= r80, < r81.10
r81.10
r81.20
r82
r82.10
r82.20
cpe:2.3:a:checkpoint:multi-domain_security_management:*:*:*:*:*:*:*:*
checkpoint quantum_security_management >= r80, < r81.10
r81.10
r81.20
r82
r82.10
r82.20
cpe:2.3:a:checkpoint:quantum_security_management:*:*:*:*:*:*:*:*
Original advisory text
Check Point Multiple Products Path Traversal Vulnerability
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.
Fix within
Internet-facing 3 days
and check for signs of compromise
Internal 3 days
and check for signs of compromise
  • Known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
20% chance of attack within 30 days
Type
CWE-22Path Traversal
Timeline
Published22 Sep 2026
Updated9 Oct 2026
First seen22 Sep 2026
Sources
CVE-2026-93616 · MITRE
CVE-2026-93616 · CISA KEV
Track software like this
Free during beta