Quantum Security Management

CVE-2026-93616: Management server zero-day allows unauthenticated script execution

A pre-authentication path traversal in the Check Point management web service lets attackers run scripts on the management server (CVSS 9.8). Check Point saw targeted exploitation from July 23, 2026, and CISA added it to KEV.

Published Updated

ExploitedYes, in CISA KEVAdded 22 Sept 2026
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 3.1 9.8
EPSS20%Chance of exploitation in 30 days
Public exploitNot known
FixAvailable

Affected and fixed versions

Product / branchFixed in
R82.20 with no Jumbo HotfixFixed build listed in Check Point sk1000171
R82.10 with Jumbo Hotfix Take 44 or lowerFixed build listed in Check Point sk1000171
R82 with Jumbo Hotfix Take 126 or lowerFixed build listed in Check Point sk1000171
R81.20 with Jumbo Hotfix Take 166 or lowerFixed build listed in Check Point sk1000171
R81.10 with Jumbo Hotfix Take 190 or lower (end of support)Fixed build listed in Check Point sk1000171
R81, R80.40, R80.30, R80.20, R80.10, R80 (end of support, all versions)No fix. Upgrade to a supported release

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

The Check Point Management web service doesn’t properly limit which files and folders a request can reach. An unauthenticated attacker can use path traversal and a file upload to place a script on the management server and run it. CVSS is 9.8, and the CVE record maps it to CWE-22.

A management server controls your gateways’ policy, so taking it over is worse than taking over one firewall. This is a zero-day: Check Point says it saw a handful of pinpointed attacks starting July 23, 2026, about two months before the fix. CISA added it to KEV on September 22 and gave federal agencies until September 25.

Check Point’s advisory covers a second, unrelated bug, CVE-2026-85102, a pre-authentication flaw in Security Gateway VPN certificate handling. Don’t confuse the two: this one hits the management server, not the gateway.

Am I affected?

You’re affected if you run Security Management on one of these, per the CVE record and Check Point:

  • R82.20 with no Jumbo Hotfix
  • R82.10 with Jumbo Hotfix Take 44 or lower
  • R82 with Jumbo Hotfix Take 126 or lower
  • R81.20 with Jumbo Hotfix Take 166 or lower
  • R81.10 with Take 190 or lower (end of support)
  • R81, R80.40, R80.30, R80.20, R80.10 and R80: all versions, all end of support

The September 16 LivePatch takes (28, or 29 on R82.20) do not fix this bug. Being on the latest LivePatch doesn’t make you safe.

Check your release and installed Jumbo Hotfix Take against that list. Check Point’s sk1000171 has the exact procedure and the fixed builds.

What to do

  1. Install the fix from sk1000171. It lists the fixed build for each branch. We could not open that page when writing this, so take the build numbers from it directly.
  2. Move off end-of-support releases. R81 and older, and R81.10 beyond Take 190, get no fix. Upgrade to a supported release.
  3. Treat a patched server as possibly compromised if it ran a vulnerable version at any time since July 23, 2026. Check Point warns that installing the fix doesn’t show whether the server was attacked earlier. Follow the hunting guidance in sk1000171.
  4. If you find signs of compromise, assume policy and stored secrets on the management server are exposed. Rebuild the server and rotate credentials and keys that it held.

Detection

Check Point published hunting guidance and indicators of compromise in sk1000171. We could not read that page, and no other source we opened lists indicators for this CVE. No IP addresses, hashes or file paths have been confirmed here.

Until you have the list, look back to July 23, 2026 for unexpected requests to the management web service, new scripts or files on the management server that you didn’t create, and unusual processes started by management services.

Sources

Page changelog

  • Full analysis published.

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.