CVE-2026-93616 Check Point Zero-Day Vulnerability Explained

Check Point patched critical Security Management zero-day CVE-2026-93616 after targeted attacks. Administrators should update affected systems and hunt for compromise.

Sep 24, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Check Point has patched CVE-2026-93616, a critical zero-day vulnerability in its Security Management software that attackers exploited before a fix was available. The flaw requires no authentication or user interaction and carries a CVSS 3.1 score of 9.8.

The vulnerability affects Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Successful exploitation can let an unauthenticated attacker upload and execute arbitrary scripts on a vulnerable management server.

Check Point disclosed CVE-2026-93616 on September 22 after identifying a handful of targeted attacks on July 23. The company released fixes with the advisory and urged affected customers to install them immediately.

CISA added CVE-2026-93616 to its Known Exploited Vulnerabilities catalog on September 22. Federal civilian agencies covered by Binding Operational Directive 26-04 have a September 25 remediation deadline.

What CVE-2026-93616 does

CVE-2026-93616 is a pre-authentication path traversal vulnerability in the Check Point Management web service. Check Point says it can allow an attacker to execute a script from an arbitrary path and load an arbitrary Java class.

The flaw is classified as CWE-22, or improper limitation of a pathname to a restricted directory. Its CVSS vector reflects network-based exploitation with low attack complexity, no required privileges, and no user interaction.

Management servers occupy a privileged position in an organization's network security architecture because they control policies and administrative functions across other systems. Check Point has not disclosed what attackers did after exploiting CVE-2026-93616, so compromise of managed gateways or other systems should not be treated as confirmed.

Smart-1 Cloud has already been patched. Quantum Force and Quantum Spark firewalls are not directly affected by CVE-2026-93616, although standalone systems that combine management and firewall functions still require remediation because the management component is affected.

Advertisement

Affected versions and fixes

Check Point lists the following Security Management releases as affected:

  • R82.20: Systems without Security Hotfix Take 1.
  • R82.10: Jumbo Hotfix Take 44 or earlier.
  • R82: Jumbo Hotfix Take 126 or earlier.
  • R81.20: Jumbo Hotfix Take 166 or earlier.
  • R81.10: Jumbo Hotfix Take 190 or earlier. This branch is end of support.
  • R81, R80.40, R80.30, R80.20, R80.10, and R80: End-of-support releases are also affected.

The current fixed releases are:

  • R82.20: Security Hotfix Take 1.
  • R82.10: Jumbo Hotfix Take 45.
  • R82: Jumbo Hotfix Take 127.
  • R81.20: Jumbo Hotfix Take 170.
  • R81.10: Jumbo Hotfix Take 192.

Administrators should use Check Point's CVE-2026-93616 security guidance to confirm the correct package and remediation steps for each deployment.

Check Point says LivePatch Takes 28 and 29 do not address CVE-2026-93616, and no LivePatch is available for the vulnerability.

What defenders should do now

Organizations running affected Check Point management products should install the appropriate hotfix and check for signs of compromise that may predate the September 22 disclosure.

Check Point also recommends restricting TCP port 19009 so that it is reachable only from trusted IP addresses. That reduces exposure but does not replace the security update.

Security teams should:

  • Identify affected Security Management, Multi-Domain Management, Log Server, Multi-Domain Log Server, SmartEvent, and standalone deployments.
  • Confirm the installed release and Jumbo Hotfix Take against Check Point's affected-version list.
  • Install the applicable September 22 security fix.
  • Restrict TCP/19009 access to trusted IP addresses.
  • Run Check Point's compromise-detection steps and review the published indicators of compromise.
  • Investigate exposed systems for suspicious activity dating back to at least July 23.

Check Point has not publicly identified the attacker, targeted organizations, affected sectors, or post-exploitation activity. The company has described the known CVE-2026-93616 activity only as a handful of targeted attacks.

Advertisement

CVE-2026-85102 is a separate exploited flaw

The September 22 advisory also covers CVE-2026-85102, another critical pre-authentication vulnerability, but the two flaws affect different components and have different exploitation timelines.

CVE-2026-85102 affects Security Gateway VPN certificate handling and can allow unauthenticated remote code execution. Check Point patched it on September 9, when the company said it had no evidence of exploitation.

Check Point says exploitation attempts against Spark customers began on September 12. The activity originated through VPN and proxy infrastructure and used certificate subjects including CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global, and CN=vpnuser,OU=users,O=global.

Those indicators apply to CVE-2026-85102 and should not be treated as indicators for CVE-2026-93616. Administrators investigating the VPN flaw should follow Check Point's separate remediation guidance.

CISA added both vulnerabilities to its KEV catalog on September 22 because of confirmed exploitation.

Check Point management flaws continue to surface

CVE-2026-93616 follows other serious vulnerabilities affecting security management infrastructure in 2026.

An earlier SmartConsole zero-day allowed unauthenticated attackers to gain administrator access to exposed Check Point Security Management Servers that lacked Trusted Client IP restrictions.

Management infrastructure has also been targeted outside the Check Point ecosystem. Recent Cisco FMC flaws were exploited to steal credentials, establish tunnels into internal networks, and ultimately deploy Qilin ransomware in one intrusion cluster.

Those incidents do not establish that the same activity occurred through CVE-2026-93616. They demonstrate why compromise checks are necessary when attackers gain access to systems that centrally manage firewall policies, credentials, and network controls.

Organizations running affected Check Point management products should patch CVE-2026-93616, restrict management access, and complete the vendor's compromise checks. Installing the update closes the vulnerability but does not determine whether a system was compromised before the fix became available.

Advertisement

Also read: Google's Chrome zero-day patch addresses another actively exploited vulnerability that organizations should prioritize.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.