Check Point: Check Point Management Server 0-Day Vulnerability Actively Exploited in Attacks

Check Point: Check Point Management Server 0-Day Vulnerability Actively Exploited in Attacks

Critical Zero-Day Exploit Targets Check Point Security Management Servers

Check Point has disclosed active exploitation of a critical zero-day vulnerability (CVE-2026-93616, CVSS 9.8) in its Security Management infrastructure. The flaw allows unauthenticated remote attackers to upload and execute arbitrary scripts on exposed Management Servers by combining directory traversal with unsafe file-upload behavior.

The vulnerability was exploited in targeted attacks on July 23, 2026, prior to public disclosure, classifying it as a zero-day. While Check Point described the activity as "pinpointed," it has not attributed the attacks or revealed the attackers' objectives, payloads, or affected organizations.

Affected Products & Versions:

  • Security Management Server
  • Multi-Domain Security Management Server
  • Log Server
  • Multi-Domain Log Server
  • SmartEvent

Vulnerable releases include:

  • R82.20
  • R82.10 Jumbo Hotfix Take 44 and earlier
  • R82 Take 126 and earlier
  • R81.20 Take 166 and earlier
  • R81.10 Take 190 and earlier
  • All R80, R80.10, R80.20, R80.30, R80.40, and R81 versions

Unaffected Systems:

  • Smart-1 Cloud (patched by Check Point)
  • Check Point Firewall Appliances
  • Check Point Spark Firewall

Mitigation & Patching:
Check Point has released emergency fixes, including:

  • R82.20 Security Hotfix
  • R82.10 Take 45
  • R82 Take 127
  • R81.20 Take 170
  • R81.10 Take 192 or later

Until patching is complete, organizations should:

  • Restrict Management Server access behind a Security Gateway or Check Point firewall.
  • Limit TCP port 19009 to trusted IP addresses.
  • Configure SmartConsole Trusted Clients to include only internal addresses.

Detection & Response:
Incident responders should:

  • Hunt for exploitation attempts across all affected servers, not just internet-facing hosts.
  • Check cpm.elg logs for unusually long usernames and correlate with FWM or MDS core dumps.
  • Search for ReflectionUtils errors indicating failed allResourceFiles map loads, examining paths for traversal sequences (e.g., "../").

Compromised Management Servers could grant attackers control over security policies and operational data, making patching a priority. Suspicious activity should prompt immediate forensic investigation, log preservation, and isolation of affected systems. Check Point’s advisory, last updated on September 22, 2026, remains the primary source for further guidance.

Source: https://cybersecuritynews.com/check-point-management-server-0-day-exploited/

Check Point Software cybersecurity rating report: https://www.rankiteo.com/company/check-point-software-technologies

"id": "CHE1790101591",
"linkid": "check-point-software-technologies",
"type": "Vulnerability",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Information Technology',
                        'name': 'Check Point',
                        'type': 'Cybersecurity Company'}],
 'attack_vector': 'Remote Exploitation',
 'date_detected': '2026-07-23',
 'date_publicly_disclosed': '2026-09-22',
 'description': 'Check Point has disclosed active exploitation of a critical '
                'zero-day vulnerability (CVE-2026-93616, CVSS 9.8) in its '
                'Security Management infrastructure. The flaw allows '
                'unauthenticated remote attackers to upload and execute '
                'arbitrary scripts on exposed Management Servers by combining '
                'directory traversal with unsafe file-upload behavior.',
 'impact': {'operational_impact': 'Potential control over security policies '
                                  'and operational data',
            'systems_affected': 'Security Management Servers, Multi-Domain '
                                'Security Management Servers, Log Servers, '
                                'Multi-Domain Log Servers, SmartEvent'},
 'recommendations': ['Immediate forensic investigation if suspicious activity '
                     'is detected',
                     'Log preservation and isolation of affected systems',
                     'Prioritize patching of vulnerable systems'],
 'references': [{'date_accessed': '2026-09-22',
                 'source': 'Check Point Advisory'}],
 'response': {'containment_measures': ['Restrict Management Server access '
                                       'behind a Security Gateway or Check '
                                       'Point firewall',
                                       'Limit TCP port 19009 to trusted IP '
                                       'addresses',
                                       'Configure SmartConsole Trusted Clients '
                                       'to include only internal addresses'],
              'enhanced_monitoring': ['Hunt for exploitation attempts across '
                                      'all affected servers',
                                      'Check *cpm.elg* logs for unusually long '
                                      'usernames and correlate with *FWM* or '
                                      '*MDS* core dumps',
                                      'Search for *ReflectionUtils* errors '
                                      'indicating failed *allResourceFiles* '
                                      'map loads, examining paths for '
                                      'traversal sequences (e.g., *"../"*)'],
              'remediation_measures': ['Apply emergency patches (R82.20 '
                                       'Security Hotfix, R82.10 Take 45, R82 '
                                       'Take 127, R81.20 Take 170, R81.10 Take '
                                       '192 or later)']},
 'title': 'Critical Zero-Day Exploit Targets Check Point Security Management '
          'Servers',
 'type': 'Zero-Day Exploit',
 'vulnerability_exploited': 'CVE-2026-93616 (Directory Traversal + Unsafe '
                            'File-Upload)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.