Check Point on Tuesday announced urgent patches for a critical-severity vulnerability in Management Server that has been exploited in the wild as a zero-day.
Tracked as CVE-2026-93616 (CVSS score of 9.8), the security defect is described as a directory traversal and file upload issue that could allow unauthenticated attackers to upload and execute arbitrary scripts on the Management Server.
“This vulnerability is exploited in the Wild. Check Point is aware of a handful of customers who have been attacked,” the cybersecurity firm warned in its advisory.
According to Check Point, the flaw impacts its Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products.
To resolve CVE-2026-93616, Check Point released the R82.20 Security Hotfix (TAR) and also included the fixes in the Jumbo Hotfix Accumulator for R82.10 (Take 45), R82 (Take 127), R81.20 (Take 170), and R81.10 (Take 192).
As a mitigation option, customers are advised to limit access to the Management Server behind a security gateway or a firewall and limit access to port TCP/19009 to trusted IP addresses. Check Point noted that standard LivePatch updates do not resolve CVE-2026-93616.
Check Point also released indicators of compromise (IoCs) to help organizations hunt for potential exploitation.
On Tuesday, the US cybersecurity agency CISA added the zero-day bug to its Known Exploited Vulnerabilities (KEV) catalog alongside CVE-2026-85102 (CVSS score of 9.8), a security defect in Check Point’s Security Gateway and Spark Firewall products that was patched on September 9.
Described as an improper validation of certificate data during VPN negotiation, CVE-2026-85102 can allow remote, unauthenticated attackers to bypass authentication and execute arbitrary code on the Security Gateway.
“Check Point disclosed the vulnerability and released fixes on September 9, 2026. At the time, we had no evidence of exploitation. We are now observing exploitation attempts against Check Point Spark customers globally. Customers who have not yet installed the fix should do so immediately,” Check Point said in a separate advisory.
In line with BOD 26-04’s requirements, federal agencies were given three days to patch both vulnerabilities after they were added to the KEV catalog.
Related: Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
Related: Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Related: WordPress Patches ‘Click2Shell’ Vulnerability
Related: Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
