Check Point Releases Emergency Fix After Zero-Day Attacks on Management Server
At a glance
- Check Point confirmed active exploitation of CVE-2026-93616.
- Emergency hotfixes were issued on September 22, 2026.
- The vulnerability has a CVSS score of 9.8.
Check Point Research identified active exploitation of a zero-day vulnerability affecting its Security Management Server, prompting the company to issue urgent security updates.
The vulnerability, tracked as CVE-2026-93616, is a pre-authentication path traversal flaw that enables attackers without credentials to upload and run arbitrary scripts on impacted Management Servers. Check Point Research confirmed that exploitation attempts were observed against a limited number of customers on July 23, 2026.
In response to the detected activity, Check Point released emergency hotfixes on September 22, 2026. These updates included a dedicated Security Hotfix for R82.20 and revised Jumbo Hotfix Take thresholds for other affected product branches.
The affected product range covers Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. The company advised immediate installation of the hotfixes and outlined temporary mitigations such as restricting access to trusted IP addresses and placing vulnerable systems behind firewalls.
What the numbers show
- Check Point observed exploitation attempts on July 23, 2026.
- Emergency hotfixes were made available on September 22, 2026.
- The vulnerability is rated 9.8 on the CVSS scale.
Check Point Research stated that the vulnerability allows unauthenticated attackers to compromise Management Servers before any authentication takes place. The company’s advisory detailed that only a handful of customers were targeted in the initial exploitation attempts.
According to the published guidance, organizations using the affected products should prioritize the application of the provided hotfixes. The advisory also recommended that, until patches are applied, access to Management Servers should be limited to trusted networks and protected by firewalls.
The company’s response included both technical fixes and operational recommendations to reduce the risk of further exploitation. These measures were outlined in the official security advisory released on September 22, 2026.
Check Point Research continues to monitor for additional exploitation attempts and has urged customers to remain vigilant and follow the recommended security steps.
* This article is based on publicly available information at the time of writing.