CISA KEV Alert 22 Sept 2026, 20:31 UTC

CISA Warns of Active Attacks on Critical Check Point Flaw

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA added CVE-2026-93616 to its Known Exploited Vulnerabilities (KEV) catalogue on 22 September 2026. The vulnerability affects multiple Check Point products, including Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent. Named the Check Point Multiple Products Path Traversal Vulnerability, it allows unauthenticated attackers to upload and execute arbitrary scripts.

The flaw is a path traversal vulnerability that can be exploited remotely without authentication. Successful exploitation enables arbitrary script upload and execution on affected systems, creating a critical risk to security management and logging infrastructure. The vulnerability has a CVSS score of 9.8 and is rated Critical. Patch availability is currently unknown, and no patch or advisory URL was provided in the available data.

CISA’s KEV listing confirms active exploitation of this vulnerability. The available information does not confirm use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 25 September 2026.

CISA requires agencies to apply mitigations in accordance with Check Point’s vendor instructions, while complying with BOD 26-04 guidance on prioritising security updates based on risk and CISA’s Forensics Triage Requirements. Agencies must follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders should evaluate each asset’s internet exposure and ensure compliance with the applicable patching guidance. Although the deadline applies directly to FCEB agencies, all organisations should review their exposure.

See the NVD entry for CVE-2026-93616 and CISA’s KEV catalogue for further details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline