Check Point has released emergency security updates for a critical zero-day vulnerability affecting its Security Management products. The flaw, tracked as CVE-2026-93616, has a CVSS score of 9.8 and is already being exploited in targeted attacks, according to Check Point.
The vulnerability is particularly concerning because it can be exploited without authentication. An attacker who reaches a vulnerable Management Server may be able to upload and execute malicious scripts and load arbitrary Java classes.
Since these systems are used to manage security policies and collect information across enterprise networks, a successful compromise could give an attacker access to a highly privileged part of the security environment.
How the Zero-Day Works
CVE-2026-93616 involves a combination of directory traversal and unsafe file-upload behavior in the Check Point Management web service.
An attacker can manipulate file paths to make the service access files from unintended locations. According to Check Point, the vulnerability can also allow an attacker to load an arbitrary Java class without first logging in.
Check Point said it has observed a small number of targeted attacks. The company reported that the activity began before the vulnerability was publicly disclosed, which is why it is classified as a zero-day. The vendor has not publicly identified the attackers or disclosed the full objectives of the observed attacks.
Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent.
Which Versions Are Affected?
Check Point lists several affected releases, including older and currently supported versions. Administrators should check their exact release and Jumbo Hotfix level against the vendor’s advisory before deciding whether their systems are vulnerable.
Check Point says the fix is included in:
- R82.10 Take 45
- R82 Take 127
- R81.20 Take 170
- R81.10 Take 192
The company has also released an R82.20 Security Hotfix. Smart-1 Cloud is not affected because the required fix has already been applied.
What Security Teams Should Do
Organizations running affected Check Point Management products should prioritize applying the appropriate security update.
Until systems can be patched, Check Point recommends keeping Management Servers behind a Security Gateway or firewall and restricting TCP port 19009 to trusted IP addresses. Trusted Clients configured in SmartConsole should also be limited to known internal addresses.
Security teams should also review logs for signs of exploitation rather than checking only internet-facing systems. Check Point provides indicators and investigation guidance that can help identify suspicious activity.
If a vulnerable Management Server shows signs of compromise, teams should preserve relevant logs and forensic data, investigate activity that occurred after the initial access, and contact Check Point Support.
The active exploitation of this vulnerability shows why management infrastructure deserves the same patching priority as internet-facing security appliances. A compromised management server can potentially provide an attacker with access to a central administrative layer of an organization’s security environment.