Check Point Patches Exploited Management Server Zero-Day
Check Point has released critical patches to address a zero-day vulnerability (CVE-2026-93616) in its Management Server, which is currently being exploited in the wild. The vulnerability allows unauthenticated attackers to upload and execute scripts. Check Point has provided indicators of compromise and urged customers to apply the fixes immediately, as CISA has added the vulnerability to its KEV catalog.
Check Point announced on Tuesday that it is releasing urgent patches for a critical-severity vulnerability in its Management Server. Tracked as CVE-2026-93616 (CVSS score of 9.8), the vulnerability is a directory traversal and file upload issue that could allow unauthenticated attackers to upload and execute arbitrary scripts on the Management Server. Check Point stated that it is aware of a handful of customers who have been attacked and is providing indicators of compromise to assist with detection and remediation.
The flaw impacts Check Point’s Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products. To resolve CVE-2026-93616, Check Point released the R82.20 Security Hotfix (TAR) and included the fixes in the Jumbo Hotfix Accumulator for R82.10 (Take 45), R82 (Take 127), R81.20 (Take 170), and R81.10 (Take 192). As a mitigation option, customers are advised to limit access to the Management Server behind a security gateway or a firewall and limit access to port TCP/19009 to trusted IP addresses. Standard LivePatch updates do not resolve CVE-2026-93616.
Check Point also released indicators of compromise (IoCs) to help organizations hunt for potential exploitation. The US cybersecurity agency CISA added the zero-day bug to its Known Exploited Vulnerabilities (KEV) catalog alongside CVE-2026-85102 (CVSS score of 9.8), a security defect in Check Point’s Security Gateway and Spark Firewall products that was patched on September 9. CVE-2026-85102 is described as an improper validation of certificate data during VPN negotiation, allowing remote, unauthenticated attackers to bypass authentication and execute arbitrary code on the Security Gateway. Check Point disclosed the vulnerability and released fixes on September 9, 2026. At the time, we had no evidence of exploitation. We are now observing exploitation attempts against Check Point Spark customers globally. Customers who have not yet installed the fix should do so immediately. In line with BOD 26-04’s requirements, federal agencies were given three days to patch both vulnerabilities after they were added to the KEV catalog.