Check Point released emergency hotfixes for CVE-2026-93616, a path-traversal flaw in its Security Management Server that lets an unauthenticated attacker upload arbitrary scripts and execute them, and confirmed the vulnerability is exploited in the wild — "Check Point is aware of a handful of customers who have been attacked". The affected product list is the reason this matters more than a single-appliance bug: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent all carry it, and the management server is the central repository that stores security policies, processes administrator changes and collects logs across an enterprise estate. The fix is the R82.20 Security Hotfix; Check Point published indicators of compromise in advisory SK1000171 and, for organisations that cannot deploy immediately, mitigation by placing the management server behind a firewall and restricting access to trusted IP addresses under SmartConsole's Trusted Clients. CISA added CVE-2026-93616 to the KEV catalog on 22 September, alongside a second Check Point flaw, CVE-2026-85102. Check Point's recent record on this product line explains the urgency: three separate management-plane flaws have been exploited since June, including two authentication bypasses linked to the Qilin ransomware affiliate and to administrator-privilege access on SmartConsole.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-23 |
| Source | Check Point |
| Reliability | Tier 1 |
| CVEs | CVE-2026-85102, CVE-2026-93616 |