Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal.

SOCtember.com

Always First. Fast SOC News.

Response · NEW YORK

Check Point Patches Actively Exploited Management Server Path Traversal

By Noah Park, Response, New York

Technicians in a network operations center. Not a photograph of a Check Point incident.
Photo: Mike Reyher

NEW YORK - Check Point Software Technologies has released urgent fixes for a critical, pre-authentication path traversal flaw in its management product line that the company says has already been exploited against a small number of customers, and the U.S. Cybersecurity and Infrastructure Security Agency has added the bug to its Known Exploited Vulnerabilities catalog.

The vulnerability is tracked as CVE-2026-93616 and carries a CVSS score of 9.8. In advisory sk1000171, Check Point describes a directory traversal and file upload issue that lets an unauthenticated attacker upload and execute arbitrary scripts on an affected Management Server. The company's research blog further characterizes the defect as a pre-authentication path traversal in the management web service that can lead to arbitrary-path script execution and loading of an arbitrary Java class. Check Point states the vulnerability is exploited in the wild and that it is aware of a handful of customers who have been attacked. In the same advisory post, Check Point Research said it had observed a handful of pinpointed attacks dated July 23, 2026.

Affected products named by Check Point include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Smart-1 Cloud is not affected because the fix is already applied there. Check Point Firewall appliances and Check Point Spark Firewall are also listed as not affected for this CVE. Affected on-premises trains include R82.20; R82.10 Jumbo Hotfix Take 44 or lower; R82 Jumbo Hotfix Take 126 or lower; R81.20 Jumbo Hotfix Take 166 or lower; R81.10 Jumbo Hotfix Take 190 or lower (end of support); and several earlier end-of-support releases. Check Point notes that LivePatch Takes 28 and 29 do not address this issue.

Remediation is available as the R82.20 Security Hotfix (TAR) and as Jumbo Hotfix Accumulator packages starting from R82.10 Take 45, R82 Take 127, R81.20 Take 170, and R81.10 Take 192. Until patched, Check Point advises limiting Management Server access behind a security gateway or firewall and restricting port TCP/19009 to trusted IP addresses, including tightening Trusted Clients in SmartConsole. The advisory also publishes log-based indicators of compromise for hunting, including long-username login patterns in cpm.elg logs and ReflectionUtils errors that show directory traversal sequences in upgrade-related paths.

CISA added CVE-2026-93616 to the KEV catalog on September 22, 2026, with a federal remediation due date of September 25, 2026. The catalog entry states that forensic triage is required under Binding Operational Directive 26-04 and that known ransomware campaign use is unknown. On the same day, CISA also listed CVE-2026-85102, a separate critical certificate-validation flaw in Check Point Security Gateway and Spark Firewall VPN handling that Check Point said it is now seeing exploited in attempts against Spark customers globally after a September 9 patch release.

For security operations teams, management-plane compromise is an identity and control-plane incident, not only an appliance patch ticket. Priority work is inventory of internet-reachable or broadly reachable management, log, and SmartEvent hosts; immediate Jumbo or R82.20 hotfix installation where supported; temporary network restriction of TCP/19009; and the log hunts Check Point documented. Confirmed or suspected exploitation should trigger review of management-issued policies, administrator accounts, and any downstream gateway push activity originating from the affected server.

Noah Park covers incident response and blue-team operations for SOCtember from New York.

Back to Response