Check Point has warned customers that attackers are exploiting a critical zero-day vulnerability in its Security Management infrastructure. Tracked as CVE-2026-93616, the flaw carries a CVSS score of 9.8 and enables an unauthenticated remote attacker to upload and execute arbitrary scripts on an exposed Management Server.
Check Point says it has identified a handful of targeted customer attacks and has released emergency fixes. The vulnerability combines directory traversal with unsafe file-upload behavior in the Check Point Management web service.
By manipulating file paths, an attacker can cause the service to execute a script from an arbitrary location and load an arbitrary Java class without first authenticating.
Successful exploitation therefore gives an external adversary a route to run attacker-controlled code on a highly privileged system that administers security policies and collects operational data.
Check Point Management Server 0-Day Exploited
Check Point described the exploitation as limited and “pinpointed,” but the activity predates public disclosure. According to the company, the observed attacks occurred on July 23, 2026, making CVE-2026-93616 a zero-day because it was abused before a security update became available. The vendor has not publicly attributed the intrusions or disclosed the attackers’ objectives, payloads, or affected organizations.
Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
Vulnerable releases include R82.20; R82.10 Jumbo Hotfix Take 44 and earlier; R82 Take 126 and earlier; R81.20 Take 166 and earlier; and the end-of-support R81.10 Take 190 and earlier. All R80, R80.10, R80.20, R80.30, R80.40, and R81 versions are also affected.
Smart-1 Cloud is not vulnerable because Check Point has already applied the fix. Check Point Firewall Appliances and Check Point Spark Firewall are also unaffected by this particular issue. Administrators should not assume LivePatch provides protection: LivePatch Takes 28 and 29 do not remediate CVE-2026-93616, and Check Point says no LivePatch will be available because of the nature of the correction.
Organizations should install the R82.20 Security Hotfix or move to a fixed Jumbo Hotfix Accumulator immediately. The correction is included in R82.10 Take 45, R82 Take 127, R81.20 Take 170, and R81.10 Take 192 or later.
Until patching is complete, management servers should remain behind a Security Gateway or Check Point firewall, while access to TCP port 19009 must be restricted to trusted IP addresses. Trusted Clients in SmartConsole should likewise contain only trusted internal addresses.
Incident responders should hunt across every affected management, logging, and SmartEvent server, not just internet-facing hosts. Check Point’s advisory provides Expert-mode commands for identifying unusually long usernames in cpm.elg logs and correlating those records with FWM or MDS core dumps.
It also recommends searching for ReflectionUtils errors stating that the service failed to load an allResourceFiles map, then examining returned paths for traversal sequences such as “../”. Either pattern may indicate an exploitation attempt and warrants immediate investigation. Positive results should trigger immediate, focused forensic investigation.
Because compromise of a management server could place a central administrative plane in an attacker’s hands, applying the hotfix should take priority over relying on access controls alone.
Teams finding suspicious log entries should preserve relevant logs and core dumps, isolate the affected server where operationally possible, assess subsequent activity, and contact Check Point Support. The vendor’s latest advisory was updated on September 22, 2026, and administrators should monitor it for further indicators or revised guidance.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

