Check Point rushes a hotfix for a management server zero-day

A path traversal bug in Check Point's management plane was already being used against customers weeks before the vendor knew it existed.

CSBadmin
2 Min Read

Check Point has shipped emergency hotfixes for CVE-2026-93616, a path traversal bug that lets an unauthenticated attacker upload and run scripts on a Security Management Server.

The vendor says a handful of customers were attacked as far back as July 23, when the flaw was still unknown. It rated the issue 9.8 under CVSS and published indicators of compromise alongside the fix.

The blast radius is broad for anyone who treats the management plane as internal. The same bug reaches Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent. Because that server holds security policies, administrator activity and logs, a compromise reaches well past the appliance itself.

Fixes land in the R82.20 Security Hotfix. Affected builds include R82.20 with no Jumbo Hotfix, R82.10 through Take 44, R82 through Take 126, R81.20 through Take 166 and R81.10 through Take 190, plus several end-of-support branches. Notably, the LivePatch takes that closed CVE-2026-91843 on September 16 do not cover this flaw.

Check Point has confirmed a second wave too. Attackers began probing CVE-2026-85102, a pre-authentication remote code execution bug in Security Gateway and Spark firewalls, from September 12. The attempts arrived through VPN services and proxies using certificates such as CN=vpn,OU=users,O=global.

Teams that cannot patch today should restrict management access to trusted IP addresses through the Trusted Clients setting in SmartConsole, and review logs for certificate-based Mobile Access logins followed by internal port scanning.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.