Cyber & AI intelligence
Wasteland.
Briefs indexed2807
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-93616 2026-09-22

Check Point Management Servers Under Active Attack: CVE-2026-93616 Enables Pre-Auth Code Execution

"CISA added CVE-2026-93616 to the Known Exploited Vulnerabilities catalog on 2026-09-22, confirming active exploitation of a critical path traversal flaw that lets unauthenticated attackers upload and execute arbitrary…"

CISA added CVE-2026-93616 to the Known Exploited Vulnerabilities catalog on 2026-09-22, confirming active exploitation of a critical path traversal flaw that lets unauthenticated attackers upload and execute arbitrary scripts on Check Point management infrastructure.

What Is It

CVE-2026-93616 is a directory traversal and file upload vulnerability (CWE-22) in Check Point Management Server. An unauthenticated attacker can traverse outside the intended upload directory, drop arbitrary scripts, and execute them on the target host.

The flaw carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, with total impact to confidentiality, integrity, and availability.

Why It Matters

CISA's SSVC assessment for this CVE records exploitation as active, automatable as yes, and technical impact as total. That combination means working exploitation is happening in the wild and can be scripted at scale against exposed hosts.

The target class makes it worse: Check Point management servers hold policy, logging, and administrative control over downstream security gateways. Pre-authentication code execution there is a control-plane compromise, not a single-host one. Known ransomware campaign use is currently listed as Unknown.

CISA has also flagged this entry as requiring Forensics Triage: organizations should assume potential compromise and collect evidence, not just patch and move on.

What's Vulnerable

Per the KEV entry: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.

Check Point lists the following Quantum Security Management versions as affected:

For the supported branches, the Take numbers above mark the last vulnerable build, with remediation delivered in the subsequent Jumbo Hotfix. For the end-of-support branches, no such fixed build should be assumed; confirm remediation status directly against sk1000171 before treating an EOS host as patched.

Patch Status

CISA set a due date of 2026-09-25: three days after the KEV listing. Required action: apply mitigations per Check Point's instructions (sk1000171), in compliance with BOD 26-04 and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure.

Note the EOS versions above: those builds are end-of-support, so upgrade to a supported release is the path, not a hotfix.

Sources