CISA added CVE-2026-93616 to the Known Exploited Vulnerabilities catalog on 2026-09-22, confirming active exploitation of a critical path traversal flaw that lets unauthenticated attackers upload and execute arbitrary scripts on Check Point management infrastructure.
What Is It
CVE-2026-93616 is a directory traversal and file upload vulnerability (CWE-22) in Check Point Management Server. An unauthenticated attacker can traverse outside the intended upload directory, drop arbitrary scripts, and execute them on the target host.
The flaw carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, with total impact to confidentiality, integrity, and availability.
Why It Matters
CISA's SSVC assessment for this CVE records exploitation as active, automatable as yes, and technical impact as total. That combination means working exploitation is happening in the wild and can be scripted at scale against exposed hosts.
The target class makes it worse: Check Point management servers hold policy, logging, and administrative control over downstream security gateways. Pre-authentication code execution there is a control-plane compromise, not a single-host one. Known ransomware campaign use is currently listed as Unknown.
CISA has also flagged this entry as requiring Forensics Triage: organizations should assume potential compromise and collect evidence, not just patch and move on.
What's Vulnerable
Per the KEV entry: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
Check Point lists the following Quantum Security Management versions as affected:
- R82.20 with no Jumbo Hotfix
- R82.10 with Jumbo Hotfix Take 44 or below
- R82 with Jumbo Hotfix Take 126 or below
- R81.20 with Jumbo Hotfix Take 166 or below
- R81.10 (EOS), through Jumbo Hotfix Take 190; end-of-support branch, and the advisory does not identify a later Take that remediates it
- R81 (EOS), R80.40 (EOS), R80.30 (EOS), R80.20 (EOS), R80.10 (EOS), R80 (EOS)
For the supported branches, the Take numbers above mark the last vulnerable build, with remediation delivered in the subsequent Jumbo Hotfix. For the end-of-support branches, no such fixed build should be assumed; confirm remediation status directly against sk1000171 before treating an EOS host as patched.
Patch Status
CISA set a due date of 2026-09-25: three days after the KEV listing. Required action: apply mitigations per Check Point's instructions (sk1000171), in compliance with BOD 26-04 and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure.
Note the EOS versions above: those builds are end-of-support, so upgrade to a supported release is the path, not a hotfix.
Sources
- CISA KEV Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93616
- NVD, CVE-2026-93616, https://nvd.nist.gov/vuln/detail/CVE-2026-93616
- Check Point Support, sk1000171, https://support.checkpoint.com/results/sk/sk1000171
- Check Point Blog, Security Advisory: Active Exploitation of CVE-2026-85102 and CVE-2026-93616, https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk