CHECK Point has released urgent patches for CVE-2026-93616, a critical directory-traversal and file-upload vulnerability in its Management Server products. Rated 9.8 by CVSS, the flaw can allow unauthenticated attackers to upload and execute arbitrary scripts. Check Point said the vulnerability is being exploited in the wild and that a handful of customers have been attacked. Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent.
The company issued the R82.20 Security Hotfix (TAR), with fixes also included in the Jumbo Hotfix Accumulator for R82.10 (Take 45), R82 (Take 127), R81.20 (Take 170) and R81.10 (Take 192). Customers can reduce exposure by placing the Management Server behind a security gateway or firewall and restricting TCP/19009 to trusted IP addresses. Check Point said standard LivePatch updates do not address the vulnerability and has published indicators of compromise for threat hunting.
The US Cybersecurity and Infrastructure Security Agency added CVE-2026-93616 to its Known Exploited Vulnerabilities catalogue alongside CVE-2026-85102, another Check Point flaw affecting Security Gateway and Spark Firewall products. Check Point said it is now observing global exploitation attempts against Spark customers, although it previously had no evidence of exploitation when fixes were released on 9 September 2026. Federal agencies were given three days to patch both vulnerabilities under BOD 26-04.