Check Point Emergency Hotfix Fixes Actively Exploited Security Management Server Flaw
Check Point Software has released an emergency security hotfix for a critical path traversal vulnerability in its Security Management Server. The flaw could allow an unauthenticated attacker to upload arbitrary scripts and execute code on a vulnerable management server.
Tracked as CVE-2026-93616, the vulnerability enables low-complexity attacks against affected Check Point systems.
Check Point Security Management Server vulnerability exploited in the wild
The Security Management Server is a central repository that stores and manages security policies, processes administrator changes, and collects system logs across a corporate network.
“This vulnerability is being exploited in the wild. Check Point is aware that a small number of customers have been attacked,” the company warned.
Security teams should check their networks for evidence of successful exploitation using the indicators of compromise provided in Check Point’s security advisory.
Since May 2024, the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have urged software companies to eliminate path traversal vulnerabilities from their products before release, stating that these security issues “have been called ‘unforgivable’ since at least 2007.”
Emergency hotfix and affected Check Point products
Check Point has addressed CVE-2026-93616 in the R82.20 Security Hotfix.
The complete list of affected products includes:
- Security Management Server
- Multi-Domain Security Management Server
- Log Server
- Multi-Domain Log Server
- SmartEvent
Temporary mitigations for vulnerable systems
Check Point also provides temporary mitigations for customers who cannot immediately deploy the hotfix. These measures include hardening vulnerable systems, deploying them behind a firewall, and restricting access to trusted IP addresses from the SmartConsole dashboard.
To configure trusted clients, use [管理と設定] > [権限と管理者] > [信頼できるクライアント] and limit access to trusted IP addresses.
Check Point’s hardening guidance provides additional information.

Recent Check Point vulnerabilities targeted by attackers
Check Point has warned customers in recent months that other vulnerabilities in its products are also being actively exploited.
Two years ago, CISA reported that a flaw in Check Point’s Quantum Security Gateway, CVE-2024-24919, was being actively exploited by ransomware gangs. An Orange Cyberdefense CERT report linked these attacks to NailaoLocker ransomware.
Qilin ransomware affiliates have also been exploiting an authentication bypass zero-day, CVE-2026-50751, since June. They have reportedly used a second authentication bypass zero-day, CVE-2026-16232, since at least July to authenticate with administrator privileges to the SmartConsole admin panel.
Two weeks ago, the Netherlands National Cyber Security Center (NCSC-NL) warned organizations to urgently patch two critical Check Point VPN flaws, CVE-2026-85102 and CVE-2026-85103, saying that “exploitation attempts are expected to occur soon.”
More recently, on Friday, Check Point released a security update for another authentication bypass, CVE-2026-16232. The flaw affects the Security Management Server and Security Gateway login process and allows an attacker to execute code with root privileges on the managed system.
Check Point has not flagged CVE-2026-16232 as actively exploited. However, the company said its security team can identify the attack by looking for the “Administrator Login Failed: Username Too Long” alert in audit logs and administrator login logs.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



