CHECK Point has released emergency hotfixes for CVE-2026-93616, a critical path-traversal vulnerability in its Security Management Server products. The company says the flaw is being exploited in the wild. Unauthenticated remote attackers can reportedly abuse it to upload and execute malicious scripts without logging in. Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent.
The management server controls security policies, administrator activity and system logs across Check Point deployments, so a successful compromise could affect wider enterprise networks. Check Point said it knows of a handful of customers that have already been attacked, while warning that the true number could be higher because some compromises may have gone undetected or unreported. Its advisory includes indicators of compromise for checking systems and logs.
The fix is provided in the R82.20 Security Hotfix, and customers are urged to install it promptly. Where immediate installation is not possible, Check Point recommends temporarily placing the vulnerable system behind a firewall and restricting access to trusted IP addresses. This can be configured in SmartConsole under Manage & Settings → Permissions & Administrators → Trusted Clients, but the company describes this only as an interim measure.