Quantum Security Management
CVE-2026-93616: Management server zero-day allows unauthenticated script execution
A pre-authentication path traversal in the Check Point management web service lets attackers run scripts on the management server (CVSS 9.8). Check Point saw targeted exploitation from July 23, 2026, and CISA added it to KEV.
Published Updated
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| R82.20 with no Jumbo Hotfix | Fixed build listed in Check Point sk1000171 |
| R82.10 with Jumbo Hotfix Take 44 or lower | Fixed build listed in Check Point sk1000171 |
| R82 with Jumbo Hotfix Take 126 or lower | Fixed build listed in Check Point sk1000171 |
| R81.20 with Jumbo Hotfix Take 166 or lower | Fixed build listed in Check Point sk1000171 |
| R81.10 with Jumbo Hotfix Take 190 or lower (end of support) | Fixed build listed in Check Point sk1000171 |
| R81, R80.40, R80.30, R80.20, R80.10, R80 (end of support, all versions) | No fix. Upgrade to a supported release |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
The Check Point Management web service doesn’t properly limit which files and folders a request can reach. An unauthenticated attacker can use path traversal and a file upload to place a script on the management server and run it. CVSS is 9.8, and the CVE record maps it to CWE-22.
A management server controls your gateways’ policy, so taking it over is worse than taking over one firewall. This is a zero-day: Check Point says it saw a handful of pinpointed attacks starting July 23, 2026, about two months before the fix. CISA added it to KEV on September 22 and gave federal agencies until September 25.
Check Point’s advisory covers a second, unrelated bug, CVE-2026-85102, a pre-authentication flaw in Security Gateway VPN certificate handling. Don’t confuse the two: this one hits the management server, not the gateway.
Am I affected?
You’re affected if you run Security Management on one of these, per the CVE record and Check Point:
- R82.20 with no Jumbo Hotfix
- R82.10 with Jumbo Hotfix Take 44 or lower
- R82 with Jumbo Hotfix Take 126 or lower
- R81.20 with Jumbo Hotfix Take 166 or lower
- R81.10 with Take 190 or lower (end of support)
- R81, R80.40, R80.30, R80.20, R80.10 and R80: all versions, all end of support
The September 16 LivePatch takes (28, or 29 on R82.20) do not fix this bug. Being on the latest LivePatch doesn’t make you safe.
Check your release and installed Jumbo Hotfix Take against that list. Check Point’s sk1000171 has the exact procedure and the fixed builds.
What to do
- Install the fix from sk1000171. It lists the fixed build for each branch. We could not open that page when writing this, so take the build numbers from it directly.
- Move off end-of-support releases. R81 and older, and R81.10 beyond Take 190, get no fix. Upgrade to a supported release.
- Treat a patched server as possibly compromised if it ran a vulnerable version at any time since July 23, 2026. Check Point warns that installing the fix doesn’t show whether the server was attacked earlier. Follow the hunting guidance in sk1000171.
- If you find signs of compromise, assume policy and stored secrets on the management server are exposed. Rebuild the server and rotate credentials and keys that it held.
Detection
Check Point published hunting guidance and indicators of compromise in sk1000171. We could not read that page, and no other source we opened lists indicators for this CVE. No IP addresses, hashes or file paths have been confirmed here.
Until you have the list, look back to July 23, 2026 for unexpected requests to the management web service, new scripts or files on the management server that you didn’t create, and unusual processes started by management services.
Sources
Page changelog
- Full analysis published.
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.