Check Point Multiple Products Path Traversal Vulnerability
CVE-2026-93616: CVSS 9.8 path traversal and file upload in Check Point Management Server enabling unauth RCE. Confirmed exploited; patches available.
- Vendor
- Check Point
- Product
- Security Management Server, Multi-Domain Management Server, Log Server, SmartEvent
- CVSS
- 9.8
- EPSS (exploit probability)
- 19.7%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
CVE-2026-93616 is a directory traversal and file upload vulnerability in Check Point’s management product line. An unauthenticated attacker can exploit the path traversal to write arbitrary scripts to the server and then execute them. No credentials are required.
Affected products: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, SmartEvent. See the Check Point advisory for affected version ranges and hotfix availability.
Severity: CVSS 9.8 (Critical) per NVD.
KEV status: CISA added CVE-2026-93616 to the Known Exploited Vulnerabilities catalog on September 22, 2026. Confirmed targeted exploitation occurred on July 23, 2026 per Check Point’s disclosure. Federal agencies under BOD 26-04 must remediate by September 25, 2026.
Patch: Check Point released emergency hotfixes. See the advisory for instructions by product version.
For full coverage see Check Point Patches Management Server Zero-Day.
