Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said.
CVE-2026-93616: a high-severity path traversal in Security Management
Check Point disclosed CVE-2026-93616 on September 22 and described it as a path traversal vulnerability in the Management Server's web service. The service "does not properly limit which files and folders a request can reach," the advisory says; an attacker who can reach that web service can upload scripts to the server and then execute them without logging in. The CVE record assigns the flaw a 9.8 out of 10 score on the CVSS scale.
Check Point also says the flaw was exploited in a small number of targeted attacks on July 23, though the advisory does not name the targets, the attackers, or what actions the attackers took after exploiting the server.
Affected Management Server versions, hotfix "takes," and the September 22 fix
The CVE record lists specific versions and Jumbo Hotfix takes as affected: R82.20 (with no Jumbo Hotfix installed), R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, and R81.10 with Jumbo Hotfix Take 190 or below — along with several end-of-support releases (R81, R80.40, R80.30, R80.20, R80.10 and R80).
Check Point's advisory, however, lists R82.20 as affected without the "no Jumbo Hotfix" qualification. The company published fixed builds and guidance in support article sk1000171 and instructed administrators to check their server release and Jumbo Hotfix take against the affected list and to install the update referenced in sk1000171. The advisory also cautions that installing the fix does not reveal whether the server was attacked prior to patching; administrators should follow the hunting guidance and indicators of compromise in sk1000171.
Earlier LivePatch activity is relevant: on September 16 Check Point fixed a different Management Server flaw, CVE-2026-91843, via LivePatch Take 28 (or Take 29 on R82.20) per a summary by France's CERT Santé. Check Point states those LivePatch takes do not remediate CVE-2026-93616.
The CVE entry also notes that CVE-2026-85103, a VPN certificate flaw fixed on September 9, affected overlapping releases; on R82.10, R82, and R81.20 the new flaw's affected list "goes one take higher" than that earlier VPN certificate flaw, meaning a server updated only to escape CVE-2026-85103 could still be vulnerable to CVE-2026-93616.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageCVE-2026-85102: ongoing VPN exploitation attempts against Spark firewalls
Separately, Check Point reported that since September 12 attackers have been attempting to exploit a VPN-related flaw tracked as CVE-2026-85102. That vulnerability, which Check Point fixed on September 9 (support article sk1000117), affects how gateways validate certificates during VPN setup and "may let an attacker who has not logged in run code on the gateway."
Check Point said the attempts targeted customers of Spark, its firewall line for small businesses, and other Security Gateway products across a set of releases (R81, R81.10, R81.10.x, R81.20, R82, R82.00.x and R82.10). The Netherlands' National Cyber Security Centre noted the flaw applies when these products use Site-to-Site VPN or Remote Access VPN.
According to Check Point, the attempts came from anonymizing infrastructure such as VPN services and proxies and used certificate subjects including:
- CN=vpn,OU=users,O=global
- CN=vpn-user,OU=users,O=global
- CN=vpnuser,OU=users,O=global
Check Point stressed that the list is not complete and that administrators should check logs for unusual certificate-based Mobile Access logins and for suspicious activity after such logins, which commonly includes internal port and service scanning. The company said customers who installed the September 9 fixes are protected but did not state whether any of the observed attempts succeeded.
Operational guidance for Management Server administrators
- Verify the server's release and Jumbo Hotfix take against the affected list in the CVE record and Check Point advisory.
- Install the fixed builds referenced in support article sk1000171 for CVE-2026-93616 and follow the hunting guidance and indicators of compromise in that article to search for post-compromise activity.
- For VPN-related attempts against Spark and Security Gateway products, follow the mitigation steps in sk1000117; where gateways cannot be patched, the Netherlands' NCSC recommends turning off implied VPN rules and restricting UDP ports 500 and 4500 to specific peer IPs for Site-to-Site VPN (note: that workaround does not apply to locally managed Spark firewalls).
- Examine Mobile Access logs for unusual certificate subjects and monitor any post-login behavior for signs of lateral scanning or internal reconnaissance.
How management-server administrators, Spark customers, and national CERTs should respond
Management-server administrators should prioritize checking Jumbo Hotfix takes and installing the sk1000171 update, and then execute the hunting steps in that support article, because installing the patch alone will not reveal whether a July 23 intrusion occurred. Spark firewall customers and small-business gateway operators should ensure the September 9 fixes (sk1000117) are applied and review Mobile Access certificate logins for the listed subjects and other anomalies. National CSIRTs and incident response teams should note the use of anonymizing infrastructure in the observed attempts and coordinate log-hunting and indicator-sharing where affected organizations report possible compromise.
Check Point's dual disclosures — a confirmed, high-scoring path traversal exploited in July and ongoing attempts against a recently fixed VPN validation bug — leave administrators with a straightforward task and a lingering unknown: install the published fixes, hunt using the guidance in sk1000171 and sk1000117, and determine whether those July 23 intrusions left traces that require remediation. The company has not named the targets, attackers, nor the post-exploitation actions, so answers will come only from defensive triage and forensic work.




