Check Point warns of Management Server zero-day exploited in attacks

Check Point warns of Management Server zero-day exploited in attacks
Check Point Software released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in Security Management Server products that allowed unauthenticated attackers to upload and run arbitrary scripts. The company said the issue is being exploited in the wild and urged customers to patch immediately or apply temporary mitigations while checking for signs of compromise. #CheckPoint #CVE-2026-93616 #SecurityManagementServer #SmartConsole

Keypoints

  • Check Point issued emergency hotfixes for a critical Security Management Server vulnerability.
  • CVE-2026-93616 is a path traversal flaw that enables arbitrary script execution.
  • The bug affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
  • Check Point said the vulnerability is being actively exploited and some customers have already been attacked.
  • Temporary mitigations include firewall hardening and restricting Trusted Clients in SmartConsole.

Read More: https://www.bleepingcomputer.com/news/security/check-point-patches-management-server-zero-day-exploited-in-attacks/