NG Solution Team
Cybersecurity

CVE-2026-93616: Check Point patches critical management zero-day

Check Point has released fixes for CVE-2026-93616, a critical zero-day in its Security Management software that was exploited before a patch was available. The flaw requires no authentication or user interaction and carries a CVSS 3.1 score of 9.8.

CVE-2026-93616 explained

CVE-2026-93616 is a pre-authentication path traversal vulnerability in the Check Point Management web service. Check Point says the flaw can allow an attacker to execute a script from an arbitrary path and to load an arbitrary Java class. The issue is classified as CWE-22, improper limitation of a pathname to a restricted directory. The CVSS vector indicates network-based exploitation with low attack complexity, no required privileges, and no user interaction.

Management servers occupy a privileged position in network security architectures because they control policies and administrative functions across other systems. Check Point has not disclosed what attackers did after exploiting CVE-2026-93616, so compromise of managed gateways or other systems should not be treated as confirmed.

Smart-1 Cloud has already been patched. Quantum Force and Quantum Spark firewalls are not directly affected by CVE-2026-93616, although standalone systems that combine management and firewall functions still require remediation because the management component is affected.

Affected versions and fixed releases

Check Point lists the following Security Management releases as affected:
R82.20: Systems without Security Hotfix Take 1.
R82.10: Jumbo Hotfix Take 44 or earlier.
R82: Jumbo Hotfix Take 126 or earlier.
R81.20: Jumbo Hotfix Take 166 or earlier.
R81.10: Jumbo Hotfix Take 190 or earlier. This branch is end of support.
R81, R80.40, R80.30, R80.20, R80.10, and R80: End-of-support releases are also affected.

The current fixed releases are:
R82.20: Security Hotfix Take 1.
R82.10: Jumbo Hotfix Take 45.
R82: Jumbo Hotfix Take 127.
R81.20: Jumbo Hotfix Take 170.
R81.10: Jumbo Hotfix Take 192.

Administrators should use Check Point’s CVE-2026-93616 security guidance to confirm the correct package and remediation steps for each deployment. Check Point says LivePatch Takes 28 and 29 do not address CVE-2026-93616, and no LivePatch is available for the vulnerability.

Response, mitigation and timeline

Check Point disclosed CVE-2026-93616 on September 22 after identifying a handful of targeted attacks on July 23. The company released fixes with the advisory and urged affected customers to install them immediately. CISA added CVE-2026-93616 to its Known Exploited Vulnerabilities catalog on September 22. Federal civilian agencies covered by Binding Operational Directive 26-04 have a September 25 remediation deadline.

Check Point recommends restricting TCP port 19009 so it is reachable only from trusted IP addresses; this reduces exposure but does not replace the security update. The vendor also published compromise-detection steps and indicators of compromise that administrators should review.

Security teams should:
Identify affected Security Management, Multi-Domain Management, Log Server, Multi-Domain Log Server, SmartEvent, and standalone deployments.
Confirm the installed release and Jumbo Hotfix Take against Check Point’s affected-version list.
Install the applicable September 22 security fix.
Restrict TCP/19009 access to trusted IP addresses.
Run Check Point’s compromise-detection steps and review the published indicators of compromise.
Investigate exposed systems for suspicious activity dating back to at least July 23.

Check Point has not publicly identified the attacker, targeted organizations, affected sectors, or post-exploitation activity. The company has described the known CVE-2026-93616 activity only as a handful of targeted attacks.

Related CVE and broader context

The September 22 advisory also covers CVE-2026-85102, a separate critical pre-authentication vulnerability. CVE-2026-85102 affects Security Gateway VPN certificate handling and can allow unauthenticated remote code execution. Check Point patched CVE-2026-85102 on September 9, when the company said it had no evidence of exploitation. Check Point says exploitation attempts against Spark customers began on September 12, originating through VPN and proxy infrastructure and using certificate subjects including CN=vpn,OU=users,O=global , CN=vpn-user,OU=users,O=global , and CN=vpnuser,OU=users,O=global. Those indicators apply to CVE-2026-85102 and should not be treated as indicators for CVE-2026-93616. CISA added both vulnerabilities to its KEV catalog on September 22 because of confirmed exploitation.

CVE-2026-93616 follows other serious vulnerabilities affecting security management infrastructure in 2026. An earlier SmartConsole zero-day allowed unauthenticated attackers to gain administrator access to exposed Check Point Security Management Servers that lacked Trusted Client IP restrictions. Management infrastructure has also been targeted outside the Check Point ecosystem. Recent Cisco FMC flaws were exploited to steal credentials, establish tunnels into internal networks, and ultimately deploy Qilin ransomware in one intrusion cluster. Those incidents do not establish that the same activity occurred through CVE-2026-93616, but they illustrate why compromise checks are necessary when attackers gain access to systems that centrally manage firewall policies, credentials, and network controls.

Organizations running affected Check Point management products should install the appropriate hotfix, restrict management access, and complete the vendor’s compromise checks. Installing the update closes the vulnerability but does not determine whether a system was compromised before the fix became available.

Related posts

Cybersecurity Breach Sparks U.S. Boarding of Texas-Bound Tanker

James Smith

Online Business Registry Restored After Belize Registry Cyber Breach

Michael Johnson

How did the Oracle PeopleSoft zero-day vulnerability lead to a data breach at Nissan Americas?

Emily Brown

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy