Back to Feed
VulnerabilitiesSep 23, 2026

Check Point Patches Exploited Management Server Zero-Day

Check Point patches critical zero-day vulnerability in Management Server exploited in the wild.

Summary

Check Point has released urgent patches for a critical-severity zero-day vulnerability (CVE-2026-93616) in its Management Server products, which has been actively exploited by attackers. The flaw allows unauthenticated attackers to upload and execute arbitrary scripts. A second vulnerability, CVE-2026-85102, affecting Security Gateway and Spark Firewall products, is also being exploited and has been added to CISA's Known Exploited Vulnerabilities catalog.

Full text

Check Point on Tuesday announced urgent patches for a critical-severity vulnerability in Management Server that has been exploited in the wild as a zero-day. Tracked as CVE-2026-93616 (CVSS score of 9.8), the security defect is described as a directory traversal and file upload issue that could allow unauthenticated attackers to upload and execute arbitrary scripts on the Management Server. “This vulnerability is exploited in the Wild. Check Point is aware of a handful of customers who have been attacked,” the cybersecurity firm warned in its advisory. According to Check Point, the flaw impacts its Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products. To resolve CVE-2026-93616, Check Point released the R82.20 Security Hotfix (TAR) and also included the fixes in the Jumbo Hotfix Accumulator for R82.10 (Take 45), R82 (Take 127), R81.20 (Take 170), and R81.10 (Take 192). As a mitigation option, customers are advised to limit access to the Management Server behind a security gateway or a firewall and limit access to port TCP/19009 to trusted IP addresses. Check Point noted that standard LivePatch updates do not resolve CVE-2026-93616.Advertisement. Scroll to continue reading. Check Point also released indicators of compromise (IoCs) to help organizations hunt for potential exploitation. On Tuesday, the US cybersecurity agency CISA added the zero-day bug to its Known Exploited Vulnerabilities (KEV) catalog alongside CVE-2026-85102 (CVSS score of 9.8), a security defect in Check Point’s Security Gateway and Spark Firewall products that was patched on September 9. Described as an improper validation of certificate data during VPN negotiation, CVE-2026-85102 can allow remote, unauthenticated attackers to bypass authentication and execute arbitrary code on the Security Gateway. “Check Point disclosed the vulnerability and released fixes on September 9, 2026. At the time, we had no evidence of exploitation. We are now observing exploitation attempts against Check Point Spark customers globally. Customers who have not yet installed the fix should do so immediately,” Check Point said in a separate advisory. In line with BOD 26-04’s requirements, federal agencies were given three days to patch both vulnerabilities after they were added to the KEV catalog. Related: Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity Related: Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers Related: WordPress Patches ‘Click2Shell’ Vulnerability Related: Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire WordPress Patches ‘Click2Shell’ VulnerabilityFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ StealerRatHat Android Trojan Uses AI for AutomationCrowdSec Confirms Source Code Stolen in Supply Chain AttackOrganizations Warned of 3 Exploited Linux Kernel VulnerabilitiesTigerByte Cyber Emerges From Stealth With $3 Million in FundingNightmareStresser DDoS Service Disrupted in International OperationBrevo Supply Chain Attack Injects Malware Into 100,000 Websites Latest News Critical F5 BIG-IP Vulnerability Exploited as Zero-DayShinyHunters Claims FBI Hack, Demands Retraction of Threat ReportBigCommerce Data Stolen via Ribon Apps HackCyera Raises $400 Million at $12+ Billion ValuationNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing IdentityOnly 13% of OT Network Segments Are Fully Isolated: AnalysisRecent ZyXEL Switch Vulnerability Exploited by Chinese HackersMalicious B-tree NPM Package Accumulates Millions of Downloads Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-93616
  • cve — CVE-2026-85102

Entities

Check Point (vendor)Management Server (product)Security Gateway (product)Spark Firewall (product)Zero-day (technology)