Hackers Exploit Check Point 0-Day Flaw to Execute Code on Management Servers
Check Point says CVE-2026-93616 is exploited to run code on unauthenticated management servers.
Check Point disclosed CVE-2026-93616, a CVSS 9.8 directory-traversal and arbitrary file-upload flaw that lets unauthenticated attackers upload and execute scripts on exposed management servers. Affected products include Security Management Server, Multi-Domain Security Management, Log Server, Multi-Domain Log Server, and SmartEvent; Smart-1 Cloud and firewall appliances are not affected. Check Point said a handful of customer environments were already attacked. Fixes are in an R82.20 security hotfix and jumbo takes R82.10 Take 45, R82 Take 127, R81.20 Take 170, and R81.10 Take 192. LivePatch does not remediate the issue.