"This vulnerability is exploited in the wild. Check Point is aware of a handful of customers who have been attacked," Check Point warned — a terse admission that a newly disclosed flaw in its central management product has already been used against live networks.
CVE-2026-93616: a path traversal zero-day that uploads and runs scripts
Check Point Software published emergency hotfixes after finding a critical Security Management Server vulnerability tracked as CVE-2026-93616. The company described the flaw as a path traversal issue that allows unauthenticated attackers to upload arbitrary scripts to vulnerable Management Servers and execute them. Check Point characterized the attack as low complexity.
Which Check Point products are affected
Check Point said the R82.20 Security Hotfix addresses CVE-2026-93616 and listed the complete set of affected products: Security Management Server, Multi‑Domain Security Management Server, Log Server, Multi‑Domain Log Server, and SmartEvent. The Security Management Server is the central repository that stores and manages security policies, processes administrator changes, and collects system logs across enterprise networks — the very plane attackers targeted.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleMitigations, hotfixes, and indicators
Check Point issued an emergency hotfix and also published temporary mitigations for organizations that cannot immediately deploy the patch. Those measures include hardening exposed systems by placing them behind a firewall and limiting access to trusted IP addresses using the Manage & Settings > Permissions & Administrators > Trusted Clients setting in the SmartConsole dashboard. The company also advised security teams to search their networks for evidence of successful exploitation using the indicators of compromise shared in the vendor's advisory.
Related active exploits, prior warnings, and vendor chronology
- Federal agencies have long warned about path traversal risks: the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI urged software companies in May 2024 to remove path traversal weaknesses before shipping, saying such security issues "have been called 'unforgivable' since at least 2007."
- Check Point has seen a string of other, recently exploited flaws. Two years ago, CISA flagged CVE-2024-24919 in Check Point's Quantum Security Gateways as actively exploited by ransomware gangs and linked those attacks to NailaoLocker via an Orange Cyberdefense CERT report.
- Since June, a Qilin ransomware affiliate has exploited an authentication bypass zero-day, CVE-2026-50751. A second authentication bypass zero-day, CVE-2026-16232, "has been exploited since at least July" to authenticate with administrator privileges to SmartConsole admin panels, according to the vendor's advisory.
- Two weeks ago the Dutch National Cyber Security Centre (NCSC-NL) warned organizations to urgently patch two critical Check Point VPN flaws (CVE-2026-85102 and CVE-2026-85103), saying it "expects exploitation attempts to occur soon."
- More recently, Check Point released security updates to address CVE-2026-16232 — described as a critical authentication bypass in the login process for Security Management Server and Security Gateways that can let attackers execute code with root privileges on management systems. The company, however, "has not yet flagged CVE-2026-16232 as actively exploited" and advised teams to look for specific login alerts.
What this means for security teams, regulators, and enterprise procurement
- Security teams: Immediate action is required where Management Servers are in scope. Apply the R82.20 Security Hotfix where possible; otherwise, implement the vendor's recommended network hardening and Trusted Clients restrictions and hunt for the vendor-provided indicators of compromise.
- Regulators and government cybersecurity units: The CISA and FBI guidance from May 2024 — and the NCSC-NL’s recent public urging — underscore continued emphasis on eliminating path traversal and authentication bypass flaws before product deployment. Those agencies' prior statements are part of the public record cited by Check Point and others.
- Enterprise procurement and IT leaders: The affected components — management, logging, and SmartEvent — are high-value targets because they control policy and collect logs. Procurement and risk teams should treat management-plane vulnerabilities and their mitigation timelines as priority elements in vendor risk assessments.
Two final, concrete notes from the advisory cycle: Check Point explicitly told customers that a "handful" of organizations had been attacked via CVE-2026-93616, and it published specific diagnostic cues for CVE-2026-16232 — including the alert text "Administrator failed to log in: Username too long" in Audit and Admin login logs — which security teams can use to detect attempts. For teams tracking the vendor's bulletins, Check Point has also offered a forum for broader discussion, including a scheduled digital summit featuring Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian that explores AI-speed attacks and defender responses.
The sequence of advisories — a path traversal zero-day with confirmed exploitation, multiple authentication bypasses, and external warnings from national CERTs — leaves one clear operational question: can organizations accelerate management-plane patching and hardening fast enough to keep their central control points from becoming beachheads for further attacks? Check Point's hotfixes and mitigations are available now; the clock on exploitation, the vendor warns, is already running.
Original story: https://www.bleepingcomputer.com/news/security/check-point-patches-management-server-zero-day-exploited-in-attacks/




