Check Point warns of Management Server zero-day exploited in attacks
Check Point patched CVE-2026-93616, an exploited unauthenticated Management Server zero-day.
Check Point released emergency hotfixes for CVE-2026-93616, a path-traversal flaw in Security Management Server that lets unauthenticated attackers upload and execute arbitrary scripts. The company said the vulnerability is exploited in the wild and that a handful of customers were attacked. Affected products include Security Management, Multi-Domain Management, Log Server, Multi-Domain Log Server, and SmartEvent; customers who cannot patch immediately should limit access to trusted IPs. The article also recounts other Check Point bugs, including CVE-2024-24919, CVE-2026-50751, CVE-2026-16232, CVE-2026-85102, and CVE-2026-85103.