Check Point Patches Exploited Management Server Zero-Day

Server Security

Check Point released emergency fixes on September 22 for CVE-2026-93616, a critical pre-authentication vulnerability in its Security Management infrastructure that the company says has already been exploited in targeted attacks.

The flaw carries a CVSS score of 9.8 and can allow an unauthenticated attacker to exploit directory traversal and file-upload weaknesses in the management web service, execute a script from an arbitrary path and load an arbitrary Java class. Check Point said it had observed a handful of targeted attacks exploiting the vulnerability.

Required action Administrators running affected Check Point management products should install the applicable security or Jumbo Hotfix immediately. Check Point says standard LivePatch Take 28/29 does not fix CVE-2026-93616.

A Zero-Day in Central Security Management

CVE-2026-93616 affects infrastructure used to centrally administer enterprise security environments. Check Point lists Security Management Server among the affected systems, while independent reporting also identifies Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent as affected products.

The significance for infrastructure operators is the location of the vulnerability. A management server handles security policies and administrative changes across protected environments, making exposure of that system different from a flaw confined to an individual endpoint.

Check Point described the exploitation as limited rather than widespread. According to its September 22 advisory, researchers observed a handful of pinpointed attacks on July 23, 2026. The company has not publicly identified the affected customers in the advisory.

Affected Versions and Fixes

Check Point has issued fixes across several supported software branches. The company’s release documentation confirms that the new Jumbo Hotfix takes published on September 22 include the CVE-2026-93616 correction.

Branch Affected level Fixed level
R82.20 Listed as affected R82.20 Security Hotfix
R82.10 Jumbo Hotfix Take 44 or earlier Take 45 or later
R82 Jumbo Hotfix Take 126 or earlier Take 127 or later
R81.20 Jumbo Hotfix Take 166 or earlier Take 170 or later
R81.10 Jumbo Hotfix Take 190 or earlier Take 192 or later

Older R80, R80.10, R80.20, R80.30, R80.40 and R81 releases are also listed as affected and are end-of-support. Operators still running those branches should follow Check Point’s upgrade and remediation guidance rather than assuming an ordinary LivePatch provides protection.

Operators Should Also Hunt for Exploitation

Installing the fix addresses future exploitation, but systems exposed before patching may require investigation. Check Point has published indicators of compromise and hunting guidance for organizations assessing whether their management infrastructure was targeted.

For environments where an immediate update cannot be completed, Check Point recommends restricting access to the Management Server behind a security gateway or firewall and limiting management access to trusted IP addresses. These measures are mitigations rather than substitutes for installing the vendor’s fix.

The U.S. Cybersecurity and Infrastructure Security Agency also added the vulnerability to its Known Exploited Vulnerabilities catalog, according to SecurityWeek, reinforcing that exploitation is based on observed activity rather than proof-of-concept availability alone.

A Second Exploited Check Point Flaw

The September 22 advisory also updated the status of CVE-2026-85102, another critical vulnerability with a CVSS score of 9.8. That flaw affects Security Gateway and Spark Firewall products and can enable unauthenticated remote code execution through improper validation of certificate data during VPN negotiation.

Check Point originally released fixes for CVE-2026-85102 on September 9, when it said there was no evidence of exploitation. The company now says exploitation attempts have been observed against Spark customers globally beginning September 12.

Administrators therefore need to distinguish between the two issues when checking their environments: CVE-2026-93616 targets Security Management infrastructure and was exploited as a zero-day, while CVE-2026-85102 affects gateway and Spark firewall systems and was exploited after a patch had already become available.

What Happens Next

The immediate priority is remediation and retrospective investigation. Operators should identify affected management servers, deploy the appropriate September 22 hotfix, review Check Point’s indicators of compromise and examine systems that were reachable before the update was installed.

Because Check Point has confirmed real-world exploitation but disclosed only a small number of attacks, the currently known scope should not be interpreted as evidence that every exposed deployment has been compromised. The company has not publicly disclosed the attackers responsible for the observed CVE-2026-93616 activity.

The fixed R82.10 Take 45, R82 Take 127 and R81.20 Take 170 packages were released on September 22, 2026.