CVE-2026-93616
Summary
A directory traversal and file-upload vulnerability in Check Point Security Management Server that allows an unauthenticated attacker to upload and execute arbitrary scripts on the server that stores security policy for an enterprise estate.
Details
NVD scores CVE-2026-93616 at CVSS 3.1 9.8 (Critical) — vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning no authentication, no user interaction and full loss of confidentiality, integrity and availability. Check Point describes it as a pre-authentication management-server flaw and released emergency hotfixes in the R82.20 Security Hotfix. Affected products are Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent.
Exploitation and defensive guidance
Check Point states the flaw "is exploited in the wild" and that it is aware of a handful of customers who have been attacked; indicators of compromise are published in advisory SK1000171, and the vendor's own advisory blog names active exploitation of both this CVE and CVE-2026-85102. Temporary mitigation for organisations that cannot deploy the hotfix immediately is to place the management server behind a firewall and restrict administrative access to trusted IP addresses via SmartConsole's Permissions & Administrators → Trusted Clients panel.
CISA added CVE-2026-93616 to the Known Exploited Vulnerabilities catalog on 22 September 2026 under Binding Operational Directive 26-04, which requires federal civilian agencies to prioritise remediation of KEV-listed flaws on publicly exposed assets that grant total control post-exploitation and to establish whether compromise preceded the patch.
Australian Significance
This is the fourth management-plane flaw exploited against Check Point products in 2026, following the Qilin-linked VPN authentication bypass (CVE-2026-50751), the SmartConsole bypass (CVE-2026-16232) and root-level code execution patched on 18 September. Australian organisations governed by APRA CPS 234 and operators of systems of national significance under the SOCI Act should treat management consoles as tier-zero assets: the consolidating risk is not the individual CVE but that each year's exploitation lands on the console from which all endpoint and gateway policy is pushed.
Related Pages
Sources: raw/digests/Cyber-Digest-2026-09-23.md