CHECK Point has warned that attackers are actively exploiting CVE-2026-93616, a critical vulnerability in its Security Management products. Rated CVSS 9.8, the flaw combines directory traversal with unrestricted file upload, allowing an unauthenticated attacker to upload a malicious payload and execute arbitrary scripts on an exposed Management Server. The attack can be launched over TCP port 19009.
Check Point said it is aware of “a handful of customers who have been attacked”; the article says vulnerability details are public, but no public proof-of-concept exploit has been confirmed.
Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent. Listed vulnerable releases include R82.20 without a Jumbo Hotfix; R82.10 with Jumbo Hotfix Take 44 or earlier; R82 with Take 126 or earlier; R81.20 with Take 166 or earlier; and end-of-support R81.10 with Take 190 or earlier. Older end-of-support releases from R80 through R81 are also affected. Smart-1 Cloud and Check Point Firewall Appliances are not affected.
Check Point has not yet issued a final fix for every affected version, and LivePatch Takes 28 and 29 do not address the issue. Administrators should place management servers behind a security gateway and restrict TCP port 19009 to trusted IP addresses, while consulting Check Point’s advisory for configuration instructions.