Check Point Releases Fixes for Critical CVE-2026-93616 Vulnerability

Check Point has released fixes for a critical vulnerability in its management servers. According to the vendor, CVE-2026-93616 was already being exploited in limited, targeted attacks in July.

The Check Point vulnerability CVE-2026-93616 is a critical flaw in the vendor’s management products, with active exploitation confirmed. Check Point said it observed limited, targeted exploitation against a handful of customers on July 23, 2026. It made a fix available on September 22.

The flaw has a CVSS score of 9.8 and affects the Management web service. It is a pre-authentication path traversal flaw, meaning it can be exploited without logging in. According to the vendor’s description, an attacker could execute a script from an arbitrary path and load an arbitrary Java class.

This is not an update to the previously published CVE-2026-91843 flaw. CVE-2026-93616 is a separate vulnerability with its own fix and vendor recommendations.

The Check Point vulnerability affects management servers

The affected products are Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. These systems are designed to centrally manage Check Point security environments, including the administration and management of security policies.

Successful exploitation could allow an unauthenticated attacker to execute their own script on an affected management server. The role of these servers in the infrastructure makes the flaw particularly serious, as they are used to manage security products.

Organizations should deploy the fixes according to Check Point security advisory sk1000171. The vendor also warned that LivePatch Take 28/29 does not fix this vulnerability.

The flaw was added to the CISA KEV catalog

The Canadian Centre for Cyber Security said that CISA added CVE-2026-93616 to the Known Exploited Vulnerabilities (KEV) catalog on September 22.

Confirmed exploitation and its addition to KEV are reasons to verify versions and fix deployment status on all affected management systems. Alongside the update, organizations should review available indicators of compromise and internal security logs according to the vendor’s recommendations.

The scope of the attacks is not yet known

Check Point has not disclosed the attackers’ identity, motivation, tools used, or the names of the affected organizations. The total number of compromised environments and the extent of any subsequent intrusion into affected networks have also not been publicly confirmed.

Further developments may bring technical details about the attacks, indicators of compromise, or information about a broader range of affected organizations. The key point is that a fix is available, and LivePatch Take 28/29 alone is not sufficient to remove the flaw.

Sources

  • Check Point Blog – The vendor confirms CVE-2026-93616, its technical nature, limited targeted exploitation on July 23, and the availability of a fix.
  • Canadian Centre for Cyber Security – The Canadian government authority says Check Point reported exploitation and that CISA added the flaw to KEV on September 22.
  • BleepingComputer – Independently describes the affected products, the ability to upload and execute scripts without authentication, and the available temporary mitigation.

Verified and updated: 09/23/2026 06:26

Sharing