Nora
Blake

Check Point CVE-2026-93616: Management Server Zero-Day Exploited in Targeted Attacks

Nora Blake

Sep 23, 2026

8 min read

Check Point CVE-2026-93616 Management Server Zero-Day Exploited in Targeted Attacks

TL;DR

Check Point CVE-2026-93616 is a critical management-server vulnerability exploited before its public disclosure, making patching and retrospective investigation essential.

  • The pre-authentication flaw can enable arbitrary script execution, with limited targeted attacks observed before fixes became available.
  • Enterprises should apply Check Point’s fixes, restrict management access, and review historical activity using vendor hunting guidance and IOCs.
  • If investigation extends to managed endpoints, Hexnode XDR can support threat hunting and containment, while Hexnode UEM supports endpoint patch and compliance workflows.

Check Point has patched CVE-2026-93616, a critical Security Management vulnerability exploited before its public disclosure. The flaw targets a sensitive part of enterprise network infrastructure: systems used to manage security policies and related operations.

Check Point observed a handful of pinpointed attacks on July 23, 2026. The company disclosed the vulnerability and released fixes on September 22.

CVE-2026-93616 combines directory traversal and file-upload weaknesses in the Check Point Management web service. An unauthenticated attacker can upload and execute arbitrary scripts. Check Point also states that the flaw can load an arbitrary Java class. The vulnerability carries a CVSS v3.1 score of 9.8.

Check Point CVE-2026-93616 at a Glance

Detail  Information 
CVE  CVE-2026-93616 
Vulnerability type  Directory/path traversal and file upload 
CVSS  9.8, CVSS v3.1 
Authentication required  No 
Potential impact  Arbitrary script execution and arbitrary Java class loading 
Observed exploitation  Yes, limited targeted attacks 
Observed attack date  July 23, 2026 
Fix released  September 22, 2026 

Check Point identifies R82.20, R82.10 Jumbo Hotfix Take 44 or lower, R82 Jumbo Hotfix Take 126 or lower, R81.20 Jumbo Hotfix Take 166 or lower, and R81.10 Jumbo Hotfix Take 190 or lower as affected. The affected end-of-support releases also include R80, R80.10, R80.20, R80.30, R80.40, and R81.

How Check Point CVE-2026-93616 Enables Script Execution

The distinctive risk in Check Point CVE-2026-93616 comes from crossing the management server’s file-path boundary before authentication.

Check Point describes the issue as a pre-authentication path traversal vulnerability in its Management web service. The weakness allows an attacker to execute a script from an arbitrary path and load an arbitrary Java class. The CVE description further identifies directory traversal combined with file upload as the underlying issue.

Therefore, an attacker does not first need an authenticated administrator session to exploit the vulnerable functionality.

However, the available Check Point advisory does not publicly document the complete request sequence used in the July attacks. It also does not identify the attackers or targeted organizations. Check Point has not detailed what the attackers did after exploitation in those incidents.

That distinction matters. The vulnerability can enable arbitrary script execution. However, publicly available reporting does not establish every post-exploitation action performed during the observed attacks.

Which Check Point Management Systems Need Attention?

Check Point’s guidance identifies several affected products. These include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.

Quantum Force and Quantum Spark firewall-only appliances are not affected by CVE-2026-93616. However, standalone deployments where management and firewall functions run on the same device are affected and should be remediated. Smart-1 Cloud has already been patched.

This Check Point Security Management Server vulnerability affects several management and logging products across supported and legacy releases.

Check Point recommends upgrading supported releases to the appropriate fixed build:

  • R82.20: Security Hot Fix Take 1
  • R82.10: Jumbo Hotfix Take 45
  • R82: Jumbo Hotfix Take 127
  • R81.20: Jumbo Hotfix Take 170
  • R81.10: Jumbo Hotfix Take 192

Administrators should also note that Check Point LivePatch Take 28/29 does not address CVE-2026-93616.

CVE-2026-85102 Adds a Separate VPN Exploitation Path

Check Point’s September 22 advisory also addresses CVE-2026-85102, a separate VPN vulnerability. It is not part of the documented CVE-2026-93616 attack chain.

CVE-2026-85102 is a separate pre-authentication remote code execution vulnerability involving certificate validation during VPN negotiation. Check Point released its fix on September 9. At that point, the company said it had no evidence of exploitation.

Starting September 12, Check Point observed exploitation attempts targeting Spark customers globally. The activity originated from anonymization infrastructure, including VPN services and proxies. Check Point also documented suspicious certificate subjects used in those attempts.

Administrators should review logs for unusual certificate-based Mobile Access logins. They should also investigate subsequent activity from suspicious users. Check Point notes that follow-up activity often involves internal port and service scanning.

However, the public advisory does not establish that CVE-2026-85102 and CVE-2026-93616 were combined during the observed attacks.

Why Patching Check Point CVE-2026-93616 Is Only the First Step

Installing the applicable Check Point fix remediates CVE-2026-93616, but it does not establish whether exploitation occurred before remediation. Check Point separately directs customers to its hunting guidance and indicators of compromise to check for compromise.

That distinction is particularly important because Check Point observed attacks as early as July 23, almost two months before public disclosure. For that reason, administrators should combine remediation with retrospective investigation.

Check Point directs customers to its support guidance for mitigations, hunting instructions, and indicators of compromise. It also recommends restricting management access so that TCP port 19009 is reachable only from trusted IP addresses.

Security teams should:

  • Identify vulnerable Check Point management systems and their installed hotfix takes.
  • Install the applicable vendor fix.
  • Restrict management interfaces according to Check Point guidance.
  • Review historical activity using Check Point’s published hunting guidance and IOCs.
  • Investigate suspicious activity rather than assuming patch installation proves the system was never compromised.
  • Assess downstream systems if investigation identifies evidence of compromise.

Where Hexnode Fits After a Management-Plane Security Incident

CVE-2026-93616 must be remediated on the Check Point management infrastructure itself. Hexnode UEM or Hexnode XDR does not replace Check Point’s hotfixes or its incident-specific hunting guidance.

However, endpoint investigation becomes relevant if evidence indicates activity has moved beyond the affected management infrastructure.

Investigate Suspicious Endpoint Activity with Hexnode XDR

Hexnode XDR provides security visibility and response across supported Windows and macOS endpoints. Its threat-hunting capabilities allow security teams to query endpoint activity and investigate suspicious behavior from one security console.

If an investigation identifies suspicious endpoint processes or files associated with a broader compromise, Hexnode XDR response actions include:

  1. Isolate Device to restrict network communication while maintaining XDR management connectivity.
  2. Kill Process to terminate an identified malicious or suspicious process.
  3. Quarantine File moves an identified malicious file to a restricted, encrypted location on the endpoint, making it inaccessible to the operating system and user.
  4. Run an on-demand Deep Scan from the console after containment to reassess device health and verify remediation status.

These capabilities can support downstream endpoint investigation and containment. However, they do not establish that Hexnode XDR detects CVE-2026-93616 exploitation on Check Point management servers.

Keep Managed Endpoints Patched and Compliant with Hexnode UEM

Hexnode UEM provides advanced patch-management capabilities for supported Windows and macOS endpoints. These include OS patch workflows on both platforms, a curated third-party application patch catalog for Windows, and app-update management for supported VPP apps on macOS.

As a result, these controls can help teams maintain the security posture of administrative workstations and other managed endpoints connected to sensitive infrastructure.

However, the Check Point Security Management hotfix must be deployed through Check Point’s supported remediation process. Generic endpoint patch management does not replace the vendor’s server-side update.

Strengthen Endpoint Visibility Beyond the Firewall

When a network security incident reaches managed endpoints, security teams need visibility into suspicious processes, files, and device activity.

Hexnode XDR can support endpoint investigation and response across supported Windows and macOS systems. Security teams can use these capabilities alongside vendor-specific remediation and investigation workflows.

Why-XDR-IS-stronger-thumbnail

Why XDR Is Stronger With UEM

See how UEM and XDR can connect endpoint management, security context, and threat response during enterprise incident workflows.

Download the whitepaper

FAQs

CVE-2026-93616 is a pre-authentication vulnerability in the Check Point Management web service. An attacker who can reach the vulnerable service does not need an authenticated administrator session to exploit the affected functionality.

No. Check Point states that a LivePatch is not available for CVE-2026-93616, and LivePatch Take 28/29 does not address the vulnerability. Administrators should install the applicable Security Hot Fix or Jumbo Hotfix for their affected Security Management release.

Quantum Force and Quantum Spark firewall-only appliances are not affected by CVE-2026-93616. However, Check Point states that standalone deployments where management and firewall functions run on the same device are affected and should be patched or remediated.

Treat Check Point Management Servers as High-Value Infrastructure

CVE-2026-93616 is significant because exploitation reaches infrastructure that organizations use to administer their security environment.

Check Point has confirmed limited exploitation. However, several important details remain undisclosed. The company has not publicly identified the attackers, victims, or complete post-exploitation activity from the July incidents.

Enterprises should therefore separate three tasks: patch the vulnerability, restrict management exposure, and investigate historical activity.

If an investigation extends to supported endpoints, Hexnode XDR can support endpoint threat hunting and containment. Meanwhile, Hexnode UEM can support broader endpoint patch and compliance workflows.

Neither replaces Check Point’s remediation and forensic guidance for the affected management infrastructure.

Share

Nora Blake

I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.