Unauthenticated RCE in Check Point Management Server via Directory Traversal and File Upload
CISA: Check Point Multiple Products Path Traversal Vulnerability
CVSS 3.1
9.8critical
EPSS
20%p97
Published
()
KEV added
AI analysis
This vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server, achieving high confidentiality, integrity, and availability through directory traversal and file upload attacks. An attacker can leverage this flaw to compromise sensitive systems and gain extensive control over the management environment. The affected scope includes all Check Point Management Server installations, with no specific version range identified in the provided data.
What to do: Upgrade to patched Check Point Management Server versions immediately; disable/block directory traversal and file upload features; audit all management server deployments and verify plugin installation status; monitor for new CVEs and update policies.
Affected
Check Point Management Server
—
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
CISA Known Exploited Vulnerability
Affected
Check Point Multiple Products
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA adds four actively exploited zero-days to KEV, forcing immediate patching of critical flaws in Check Point, Arista, and F5 systems.
CISA has added four actively exploited zero-day vulnerabilities to its KEV catalog, forcing US federal agencies to patch by September 25. The list includes critical flaws in Check Point Security Management (CVE-2026-93616) and Security Gateway (CVE-2026-85102), alongside zero-days in Arista VeloCloud Orchestrator (CVE-2026-93952) and F5 BIG-IP APM (CVE-2026-94127). Check Point confirmed exploitation against Management Servers and Spark firewalls globally.
CISA says two Check Point flaws, including unauthenticated remote code execution, are being exploited.
CISA added two actively exploited Check Point vulnerabilities to the Known Exploited Vulnerabilities catalog on September 22, 2026, with a September 25 remediation deadline. CVE-2026-85102 is an improper certificate validation flaw in Security Gateway and Spark Firewall Site-to-Site or Remote Access VPN that lets an unauthenticated attacker execute arbitrary code. CVE-2026-93616 is a path traversal bug in management and logging products, including Security Management Server and SmartEvent, that allows unauthenticated upload and execution of arbitrary scripts. CISA says ransomware use is unknown and urges patching, exposure checks, and forensic review.
Check Point confirms active exploitation of two CVSS 9.8 VPN and management flaws enabling unauthenticated code execution.
Check Point says attackers are exploiting two CVSS 9.8 vulnerabilities that allow unauthenticated remote access and possible remote code execution. CVE-2026-85102, patched September 9, 2026, stems from improper VPN certificate validation on Security Gateway and Spark Firewall; exploitation attempts against Spark customers began September 12 from VPN and proxy infrastructure. Newly disclosed zero-day CVE-2026-93616 is a pre-authentication directory traversal and file-upload flaw in Security Management and Multi-Domain Security Management, with a handful of customers targeted. Smart-1 Cloud, firewall appliances, and Spark are not affected by the management flaw; R82.20 is unaffected by the VPN issue.
CISA says two critical Check Point VPN and management flaws are exploited in the wild.
CISA added CVE-2026-85102 and CVE-2026-93616 to the Known Exploited Vulnerabilities catalog and urged patching before September 25, 2026. CVE-2026-85102 (CVSS 9.8) is an authentication bypass and remote code execution flaw in Check Point Remote Access and Site-to-Site VPN caused by improper certificate validation, letting unauthenticated attackers run code on Security Gateway. CVE-2026-93616 (CVSS 9.8) is a directory traversal and file-upload bug that lets unauthenticated attackers upload and execute scripts on the Management Server. Check Point patches are available; Qualys QIDs 388806 and 388699 detect vulnerable assets.
Check Point says attackers exploited unauthenticated Management Server zero-day CVE-2026-93616 in targeted July attacks.
Check Point said attackers exploited CVE-2026-93616, a CVSS 9.8 path-traversal flaw in Security Management Server, in a handful of targeted attacks on July 23. An unauthenticated attacker who can reach the web service can upload and run scripts. Fixes shipped September 22; earlier LivePatch takes for CVE-2026-91843 do not address it. Separately, attempts against VPN flaw CVE-2026-85102 have targeted Spark and Security Gateway customers since September 12, though success is unconfirmed.
Check Point says attackers exploited critical Management Server zero-day CVE-2026-93616 for unauthenticated code execution.
Check Point says attackers exploited CVE-2026-93616, a CVSS 9.8 zero-day in its Security Management infrastructure, before a fix was available. Directory traversal combined with unsafe file upload lets an unauthenticated remote attacker upload and execute arbitrary scripts and load an arbitrary Java class. A handful of targeted attacks were observed on July 23, 2026. Affected releases span Security Management, Multi-Domain Management, Log Server, and SmartEvent, including listed R82, R81, and older R80 versions; Smart-1 Cloud and Check Point firewall appliances are unaffected. LivePatch does not remediate it, so administrators must install the listed fixed Jumbo takes or the R82.20 hotfix and restrict TCP port 19009.
CISA added two actively exploited Check Point flaws, including unauthenticated VPN code execution, to KEV.
CISA added CVE-2026-85102 and CVE-2026-93616 to the KEV catalog on September 22, 2026, warning both are actively exploited, with a federal deadline of September 25 under BOD 26-04. CVE-2026-85102, CVSS 9.8, is improper certificate validation in Check Point Quantum Security Gateway and Spark Firewall VPN configurations, allowing an unauthenticated attacker to execute arbitrary code during VPN negotiation. CVE-2026-93616 is a path traversal in Security Management Server, Multi-Domain Security Management, log servers, and SmartEvent that allows unauthenticated upload and execution of arbitrary scripts. Both entries require forensic triage. CISA has not linked either flaw to ransomware.
Check Point confirms active exploitation of pre-auth VPN RCE CVE-2026-85102 and zero-day CVE-2026-93616, now both in CISA KEV.
Check Point confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution flaw in Security Gateway VPN certificate handling. The advisory also says CVE-2026-93616, a pre-authentication path traversal in the Management web service that can allow script execution and Java class loading, has been exploited as a zero-day since July 23, 2026. Attempts against Spark customers began on September 12 from VPN and proxy infrastructure, using observed certificate subjects such as CN=vpn, OU=users, O=global. CISA added both vulnerabilities to the KEV catalog and told federal agencies to remediate by September 25, 2026; fixes include LivePatch Take 26 and specified Jumbo Hotfix takes.
Check Point patched exploited zero-day CVE-2026-93616 in Management Server, and CISA added it and CVE-2026-85102 to KEV.
Check Point released urgent patches for CVE-2026-93616, a CVSS 9.8 directory traversal and file-upload flaw in Management Server that lets unauthenticated attackers upload and execute arbitrary scripts. The company said a handful of customers were attacked and that the bug affects Security Management, Multi-Domain Management, Log Server, and SmartEvent products. Fixes are in the R82.20 hotfix and Jumbo Hotfix Accumulator takes for R82.10, R82, R81.20, and R81.10; LivePatch does not cover it. CISA added CVE-2026-93616 and CVE-2026-85102, a CVSS 9.8 VPN certificate-validation bug now seeing exploitation attempts against Spark firewalls, to the KEV catalog, giving federal agencies three days to patch.
Attackers are exploiting two pre-authentication Check Point firewall flaws rated CVSS 9.8.
Check Point said attackers are actively exploiting CVE-2026-85102, a pre-authentication remote code execution flaw in Spark small-business firewalls triggered by a malicious certificate during VPN negotiation, and CVE-2026-93616, a pre-authentication path-traversal zero-day in the Security Management web service that can execute scripts and load an arbitrary Java class. Both are rated CVSS 9.8. Targeted attacks on the management flaw were observed on 23 July, with a fix about two months later; the Spark bug was patched on 9 September and exploited by 12 September. Both were added to the known-exploited vulnerability catalog, and Check Point urges immediate patching plus hunts for anomalous certificate logins and internal scans.
Check Point issued emergency hotfixes for actively exploited critical path traversal CVE-2026-93616 in Security Management Server.
Check Point released emergency hotfixes (R82.20 Security Hotfix) for CVE-2026-93616, a critical unauthenticated path traversal flaw allowing attackers to upload and execute malicious scripts on Security Management Servers, and confirmed exploitation in the wild against a handful of customers. Affected products include Security Management Server, Multi-Domain Security Management, Log Server, Multi-Domain Log Server, and SmartEvent, with IOCs published in the advisory. The flaw follows two earlier critical Check Point issues: CVE-2026-16232 (actively exploited auth bypass) and the Dutch NCSC warning covering CVE-2026-85102 and CVE-2026-85103.
Check Point says CVE-2026-93616 is exploited to run code on unauthenticated management servers.
Check Point disclosed CVE-2026-93616, a CVSS 9.8 directory-traversal and arbitrary file-upload flaw that lets unauthenticated attackers upload and execute scripts on exposed management servers. Affected products include Security Management Server, Multi-Domain Security Management, Log Server, Multi-Domain Log Server, and SmartEvent; Smart-1 Cloud and firewall appliances are not affected. Check Point said a handful of customer environments were already attacked. Fixes are in an R82.20 security hotfix and jumbo takes R82.10 Take 45, R82 Take 127, R81.20 Take 170, and R81.10 Take 192. LivePatch does not remediate the issue.
Check Point patched CVE-2026-93616, an exploited unauthenticated Management Server zero-day.
Check Point released emergency hotfixes for CVE-2026-93616, a path-traversal flaw in Security Management Server that lets unauthenticated attackers upload and execute arbitrary scripts. The company said the vulnerability is exploited in the wild and that a handful of customers were attacked. Affected products include Security Management, Multi-Domain Management, Log Server, Multi-Domain Log Server, and SmartEvent; customers who cannot patch immediately should limit access to trusted IPs. The article also recounts other Check Point bugs, including CVE-2024-24919, CVE-2026-50751, CVE-2026-16232, CVE-2026-85102, and CVE-2026-85103.
CISA added four actively exploited Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its KEV catalog, with federal fixes due September 25.
CISA added CVE-2026-85102 (Check Point VPN certificate validation bypass), CVE-2026-93616 (Check Point Security Management Server path traversal), CVE-2026-93952 (Arista VeloCloud Orchestrator input validation), and CVE-2026-94127 (F5 BIG-IP APM heap buffer overflow) to the KEV catalog. Check Point stated CVE-2026-93616 is exploited in the wild with a handful of customers already attacked, and F5 confirmed exploitation of CVE-2026-94127 against APM OAuth Authorization Server configurations. Federal agencies must remediate by September 25, 2026 under BOD 22-01. Check Point has shipped LivePatch/Jumbo Hotfixes and an R82.20 Security Hotfix, plus IOCs for detection.
Weekly roundup leads with a Gyazo breach of 23.6 million users and the TASK#STOMP document-stealing backdoor.
Helpfeel confirmed that hackers exploited a Gyazo server flaw and stole 23.6 million user records. The same weekly digest details TASK#STOMP, a Windows backdoor that uploads business documents and also takes Wi-Fi passwords, clipboard text, and screenshots. A Chinese-speaking actor exploited CVE-2026-7273 on 996 unpatched Zyxel GS1900 switches in 48 countries, and Check Point said CVE-2026-93616 has been exploited since July 23, 2026. Elsevier domains were briefly redirected to a LAPSUS$ page, while DarkMe is now spread by ordinary phishing email.
CISA added four actively exploited Check Point, Arista VeloCloud, and F5 BIG-IP flaws to the KEV catalog.
On 2026-09-22, CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. They are CVE-2026-85102 (Check Point improper certificate validation), CVE-2026-93616 (Check Point path traversal), CVE-2026-93952 (Arista VeloCloud Orchestrator improper input validation), and CVE-2026-94127 (F5 BIG-IP APM heap-based buffer overflow). Binding Operational Directive 26-04 requires federal civilian agencies to prioritize remediation of high-risk KEV entries on exposed assets. CISA encourages all organizations to remediate these cataloged flaws quickly.