{"id":948,"date":"2026-09-25T21:22:37","date_gmt":"2026-09-25T21:22:37","guid":{"rendered":"https:\/\/seoscanpro.ai\/blog\/check-point-security-management-server-zero-day\/"},"modified":"2026-09-25T21:22:38","modified_gmt":"2026-09-25T21:22:38","slug":"check-point-security-management-server-zero-day","status":"publish","type":"post","link":"https:\/\/seoscanpro.ai\/blog\/check-point-security-management-server-zero-day\/","title":{"rendered":"Check Point Patches Security Management Server Zero-Day Exploited in the Wild"},"content":{"rendered":"<p>Security teams running Check Point infrastructure can lock down a critical remote code execution path after the vendor shipped emergency hotfixes for a path traversal zero-day that is already being exploited against enterprise customers. The flaw, tracked as CVE-2026-93616, sits in the Security Management Server and lets unauthenticated attackers upload and run arbitrary scripts, so applying the R82.20 Security Hotfix closes one of the most direct routes an attacker has into a Check Point environment today.<\/p>\n<h2>What the vulnerability allows<\/h2>\n<p>CVE-2026-93616 is a path traversal flaw in Check Point&#8217;s Security Management Server, the central component that stores security policies, processes administrator changes, and collects logs across enterprise networks. Because the bug is reachable without credentials and can be exploited with low attack complexity, an attacker who reaches a vulnerable management server can upload a script of their choice and execute it on the underlying system.<\/p>\n<p>CISA and the FBI have publicly pressed software vendors since May 2024 to remove path traversal weaknesses before shipping, calling such flaws unforgivable defects that have been known and warned about since at least 2007.<\/p>\n<h2>Which products are affected<\/h2>\n<p>Check Point lists the full set of vulnerable products as:<\/p>\n<ul>\n<li>Security Management Server<\/li>\n<li>Multi-Domain Security Management Server<\/li>\n<li>Log Server<\/li>\n<li>Multi-Domain Log Server<\/li>\n<li>SmartEvent<\/li>\n<\/ul>\n<p>All of these components share the same underlying management code path, so the hotfix should be applied consistently across the management tier rather than treated as a single-product fix.<\/p>\n<h2>Active exploitation against a handful of customers<\/h2>\n<p>Check Point confirmed that the vulnerability is being exploited in the wild and that the company is aware of a handful of customers who have been attacked. The first wave of exploitation attempts was observed on September 12, with the activity targeting Spark customers in particular. The vendor has shared indicators of compromise in its security advisory so defenders can search their environments for signs of prior access.<\/p>\n<p>Because the management tier stores policies, administrator credentials, and logs, any successful intrusion into a Security Management Server typically grants the attacker broad visibility into the rest of the network. Treating the hotfix as urgent, rather than routine, is consistent with the exposure an attacker gains once they are inside.<\/p>\n<h2>Temporary mitigations while patching<\/h2>\n<p>For organizations that cannot deploy the hotfix immediately, Check Point recommends hardening the management environment by placing the server behind a firewall and limiting access to trusted IP addresses through the Manage Settings, Permissions, Administrators, Trusted Clients section of the SmartConsole dashboard. The vendor also pointed administrators at its indicators of compromise so teams can hunt for evidence that an attacker already reached the server before mitigations were applied.<\/p>\n<h2>Pattern of recent Check Point zero-days<\/h2>\n<p>CVE-2026-93616 lands in a stretch of 2026 that has already produced several exploited flaws across the Check Point product line:<\/p>\n<ul>\n<li>An authentication bypass, CVE-2026-50751, has been exploited since June by a Qilin ransomware affiliate.<\/li>\n<li>A second authentication bypass, CVE-2026-16232, has been exploited since at least July and lets attackers authenticate to SmartConsole admin panels with administrator privileges. Check Point also released a separate fix for this same CVE just before the management server advisory. Successful exploitation leaves a recognizable trace: &#8220;Administrator failed to log in: Username too long&#8221; alerts in the Audit and Admin login logs.<\/li>\n<li>Two critical VPN flaws, CVE-2026-85102 and CVE-2026-85103, prompted an urgent patching warning from the Dutch National Cyber Security Centre (NCSC-NL) earlier in the month.<\/li>\n<li>Two years earlier, CISA flagged CVE-2024-24919 in Check Point Quantum Security Gateways as actively exploited, with Orange Cyberdefense CERT linking those attacks to NailaoLocker ransomware.<\/li>\n<\/ul>\n<p>Each of these flaws targets a different layer of the Check Point stack, from VPN gateways to SmartConsole login, but together they show how consistently attackers are probing the vendor&#8217;s management and remote access surface. For security teams, that means patching CVE-2026-93616 is best treated as part of a broader review of the Check Point estate, not a one-off maintenance task.<\/p>\n<h2>What to do next<\/h2>\n<p>The fastest path to closing the exposure is installing the R82.20 Security Hotfix on every Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent instance in the environment. While the patch is being staged, restricting Trusted Clients to known IP ranges and pulling the management server behind a firewall cuts off the unauthenticated path attackers are using today. Reviewing the published indicators of compromise against historical logs gives defenders a way to tell whether any of the September 12 activity already reached a server that has not yet been patched.<\/p>\n<p>Security teams that also run SmartConsole should pull the Audit and Admin login logs for the &#8220;Username too long&#8221; alert pattern to rule out exploitation of CVE-2026-16232, and they should verify that the earlier VPN fixes for CVE-2026-85102 and CVE-2026-85103 are in place.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is CVE-2026-93616?<\/h3>\n<p>CVE-2026-93616 is a critical path traversal vulnerability in Check Point&#8217;s Security Management Server that lets unauthenticated attackers upload and execute arbitrary scripts with low attack complexity.<\/p>\n<h3>Which Check Point products are affected by CVE-2026-93616?<\/h3>\n<p>Check Point lists Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent as the affected products covered by the R82.20 Security Hotfix.<\/p>\n<h3>Is CVE-2026-93616 being actively exploited?<\/h3>\n<p>Yes. Check Point confirmed the vulnerability is exploited in the wild and that a handful of customers have been attacked, with the first wave of exploitation attempts observed on September 12 against Spark customers.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is CVE-2026-93616?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CVE-2026-93616 is a critical path traversal vulnerability in Check Point's Security Management Server that lets unauthenticated attackers upload and execute arbitrary scripts with low attack complexity.\"}},{\"@type\":\"Question\",\"name\":\"Which Check Point products are affected by CVE-2026-93616?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Check Point lists Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent as the affected products covered by the R82.20 Security Hotfix.\"}},{\"@type\":\"Question\",\"name\":\"Is CVE-2026-93616 being actively exploited?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. Check Point confirmed the vulnerability is exploited in the wild and that a handful of customers have been attacked, with the first wave of exploitation attempts observed on September 12 against Spark customers.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/check-point-patches-management-server-zero-day-exploited-in-attacks\/\" target=\"_blank\" rel=\"nofollow noopener\">bleepingcomputer.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Check Point released emergency hotfixes for a critical path traversal flaw in Security Management Server that is being actively exploited against enterprise<\/p>\n","protected":false},"author":1,"featured_media":947,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rank_math_title":"Check Point Management Server Zero-Day Patched","rank_math_description":"Check Point patched CVE-2026-93616, a path traversal zero-day in Security Management Server that attackers are using to run scripts on enterprise networks.","rank_math_focus_keyword":"check point zero-day","rank_math_canonical_url":"","rank_math_facebook_title":"","rank_math_facebook_description":"","rank_math_twitter_title":"","rank_math_twitter_description":"","rank_math_robots":[],"footnotes":""},"categories":[14],"tags":[],"class_list":["post-948","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-news"],"_links":{"self":[{"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/posts\/948","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/comments?post=948"}],"version-history":[{"count":1,"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/posts\/948\/revisions"}],"predecessor-version":[{"id":949,"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/posts\/948\/revisions\/949"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/media\/947"}],"wp:attachment":[{"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/media?parent=948"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/categories?post=948"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seoscanpro.ai\/blog\/wp-json\/wp\/v2\/tags?post=948"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}