Check Point Management Servers face active CVE-2026-93616 attacks

LinkLoot editorial cover.LinkLoot editorial cover
LinkLoot editorial cover.LinkLoot editorial cover
Tools & Apps

CVE-2026-93616 lets unauthenticated attackers upload and execute scripts on affected Check Point Management Servers. CISA lists active exploitation and sets a September 25 remediation deadline.

CISA lists CVE-2026-93616 as actively exploited and automatable, with a September 25, 2026 remediation deadline. The critical vulnerability affects Check Point Management Server products and lets an unauthenticated attacker upload and execute arbitrary scripts through a directory-traversal and file-upload chain.

CVE-2026-93616 reaches the management plane

The NIST record assigns the flaw a CVSS 3.1 score of 9.8. Its attack vector is network-based, requires no privileges or user interaction, and can affect confidentiality, integrity, and availability. The affected product family includes Quantum Security Management deployments across several R80 and R81 branches, including older end-of-life releases.

That combination makes the management server the urgent asset to inventory. The advisory does not describe a compromise of Check Point firewall appliances or Spark appliances themselves. Smart-1 Cloud is listed as already fixed, but administrators should still confirm the current service state rather than infer coverage from the product name.

What Check Point administrators should do now

Prioritize the vendor mitigation and hotfix guidance before the CISA deadline. Restrict management-server access behind a Security Gateway or Check Point Firewall, and limit trusted clients to internal IP ranges. Treat internet-exposed management interfaces as an incident-priority review item until the relevant fix or mitigation is in place.

Check Point also provides a detection command for possible exploitation attempts:

grep -E "ERROR.*upgrade\.base\.ReflectionUtils.*Failed to load allResourceFiles map from" $MDS_FWDIR/log/cpm.elg*

An output match does not prove compromise by itself. It does provide a concrete starting point for reviewing suspicious paths, preserving logs, and escalating to the organization’s incident-response process. Keep forensic copies before cleanup changes the evidence.

The deadline is September 25

CISA’s catalog entry requires federal agencies to apply vendor instructions under BOD 26-04 and calls out asset exposure and forensic triage. Private-sector teams can use the same deadline as a practical prioritization marker, especially where Management Servers are reachable from untrusted networks or administer multiple security domains.

The immediate question is not whether a deployment uses Check Point in general; it is which Management Server versions and hotfix levels are exposed, whether the management interface is reachable, and whether logs show traversal attempts. Confirm those three facts before closing the incident or declaring the environment covered.

Evidence

This report uses the CISA KEV feed, the NIST CVE record, and Check Point advisory SK1000171. The vendor page reports exploitation in the wild and provides product-specific mitigation and detection guidance; NIST and CISA independently confirm the vulnerability, severity, active-exploitation status, and deadline.

From reading to doing

Try the related loot

Give Any Model a Sandboxed Shell and File Workspace with OpenRouter

Open loot