XHack Logo
XHack
Products
Services
Compliance
Pricing
Resources
Company
Sign upLogin
XHack Logo
XHackOffensive Security

Certified offensive security team delivering penetration testing evidence written for your auditor.

OSCP+OSCPC-AI/MLPenCASA
support@xhack.io

24/7 SOC Operations

XHack Status
Under attack? Get help now
Services
  • VAPT Services
  • Red Teaming
  • SOC Services
  • Threat Intelligence
  • Incident Response
  • Managed Testing
Pricing
  • Platform Plans
  • Services Pricing
Compliance
  • SOC 2
  • PCI DSS
  • ISO 27001
  • GDPR
  • HIPAA
  • ISO 42001
  • AI Maturity Assessment
  • TX-RAMP
  • NBFC / SECP
  • All Frameworks
Products
  • Vulnerability Assessment
  • GitGuard
  • AI Probe
  • SOC Dashboard
  • AI Agent
  • Cloud Investigation
Comparison
  • XBOW vs XHack
  • Horizon3 vs XHack
  • Strix vs XHack
  • Pentera vs XHack
Resources
  • Platform Tour
  • All Features
  • Install the Agent
  • XHack AI
  • Documentation
  • Blog
  • Case Studies
  • Documents
  • FAQ
Company
  • About Us
  • Our Team
  • Certifications
  • Security and Trust
  • VAPT Explained
  • Contact

© 2026 XHack. All rights reserved.

Security & TrustVulnerability DisclosurePrivacy PolicyTerms of ServiceRefund Policy
Blog/News

CVE-2026-93616: The Critical Check Point Management Server Zero-Day

XHack

XHack

Author

October 6, 2026

13 min read

CVE-2026-93616: The Critical Check Point Management Server Zero-Day

Table of contents

17

Why the Server Behind CVE-2026-93616 Is the Prize

What CVE-2026-93616 Is, According to Check Point

The 61-Day Gap Behind CVE-2026-93616

What Check Point’s Log Sample Says About the CVE-2026-93616 Mechanism

Who Is Affected by CVE-2026-93616

How to Fix CVE-2026-93616

Hunting for CVE-2026-93616 Exploitation

The Other Half of the CVE-2026-93616 Advisory: CVE-2026-85102 and Check Point’s 2026 KEV Run

How XHack Reads CVE-2026-93616

FAQ: CVE-2026-93616 Questions Answered

What is CVE-2026-93616?

Is CVE-2026-93616 being exploited?

Which Check Point products does CVE-2026-93616 affect?

How do I fix CVE-2026-93616?

How do I check whether CVE-2026-93616 was used against me?

Does CVE-2026-93616 affect Check Point firewalls?

The Bottom Line

Read this in 30 seconds: CVE-2026-93616 is a CVSS 9.8 pre-authentication flaw in Check Point’s Security Management software, and Check Point says it was exploited as a zero-day.

  • It was used for 61 days before a fix existed. Check Point Research saw “pinpointed” attacks on July 23, 2026. The fix and advisory landed September 22.
  • No login is needed. A directory traversal and file upload bug in the management web service lets an unauthenticated attacker upload and run scripts on the server that controls your firewalls.
  • A LivePatch will not save you. Check Point says LivePatch Take 28/29 does not address it. You need a Jumbo Hotfix take or the R82.20 security hotfix.
  • The mitigation is network access control. Limit TCP/19009 to trusted IP addresses, then run Check Point’s two hunt checks on every management and log server.
  • CISA flagged it for forensic triage. Added to KEV on September 22, due September 25, which was 11 days ago.

The box that writes the rules for your firewalls is not supposed to be the weak point, and CVE-2026-93616 is what it looks like when it is.

Check Point published advisory sk1000171 for CVE-2026-93616 on September 22, 2026. It says an unauthenticated attacker can upload and execute arbitrary scripts on a Check Point Management Server, that the bug is exploited in the wild, and that Check Point knows of “a handful of customers who have been attacked.”

This article walks through what the vendor confirms, what its own log sample reveals about how the bug works (clearly labeled as our reading), who is affected, and the exact checks to run today.

CVE-2026-93616 severity summary: Check Point Security Management Server, CVSS 9.8, unauthenticated directory traversal and file upload, exploited as a zero-day since July 23 2026, added to CISA KEV September 22 2026
CVE-2026-93616 at a glance: a pre-auth zero-day in Check Point’s management plane

Why the Server Behind CVE-2026-93616 Is the Prize

A Check Point Security Management Server is the system administrators use to define security policy and push it out to the gateways. Log Servers and SmartEvent collect and correlate what those gateways see. That role is general product knowledge, not something the advisory spells out, but it explains why this class of bug matters.

An attacker who gets code execution on a gateway controls one choke point. An attacker who lands it on the management server is sitting next to the policy, the administrator accounts, and the logs for every gateway it manages. That is our reasoning about the role, not a claim from Check Point about what the attackers did next. The advisory does not say what they did after the initial access.

CVE-2026-93616 affects exactly that tier: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. The gateways themselves are not the target here.

What CVE-2026-93616 Is, According to Check Point

Check Point’s advisory sk1000171 describes CVE-2026-93616 as a directory traversal and file upload flaw that lets an unauthenticated attacker upload and run arbitrary scripts on the Management Server. The NVD record carries the same description, supplied by Check Point as the CNA.

The facts we can confirm from primary sources:

  • Weakness: CWE-22, path traversal.
  • Score: CVSS 3.1 base 9.8, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The score in the NVD record comes from Check Point, not from NVD’s own analysts.
  • Exploited: yes. The advisory says “This vulnerability is exploited in the Wild.”
  • CISA’s read: the CISA coordinator’s SSVC entry in NVD lists exploitation as active, automatable as yes, and technical impact as total.
  • Forensics: the KEV entry carries CISA’s forensic-triage flag. Known ransomware use is listed as unknown.
  • Check Point’s blog adds: the flaw is in the management web service, and lets an attacker “execute a script from an arbitrary path” and load an arbitrary Java class.

Check Point has not named the targets or the attackers. The advisory pages we read name neither, and The Hacker News reports the same.

The 61-Day Gap Behind CVE-2026-93616

The dates matter more than usual here, because CVE-2026-93616 was a zero-day in the plain sense: attacks came first.

  • July 23, 2026: Check Point Research observed “a handful of pinpointed attacks,” per Check Point’s security blog.
  • September 9: Check Point disclosed and fixed the sister bug, CVE-2026-85102, in its VPN stack.
  • September 12: exploitation attempts against that VPN bug began.
  • September 20: sk1000171 was created.
  • September 22: advisory and fix published, and CISA added CVE-2026-93616 to KEV the same day.
  • September 25: CISA’s federal deadline passed.

From July 23 to September 22 is 61 days, by our count. Check Point also reports the exploitation as a handful of targeted attacks, not mass scanning. That is the vendor’s characterization of what it saw, and it can only describe what Check Point itself observed.

CVE-2026-93616 timeline: first attacks July 23, sister VPN bug fixed September 9, advisory and CISA KEV September 22, federal deadline September 25, 61 days from first observed attack to fix
61 days from first observed attack to a public fix

What Check Point’s Log Sample Says About the CVE-2026-93616 Mechanism

Check Point has not published the request format or the vulnerable code for CVE-2026-93616, and this is closed-source software, so we can’t show you the bug. What it did publish is an indicator, and the example output in that indicator is informative.

The second indicator in sk1000171 tells you to search cpm.elg* for an error from upgrade.base.ReflectionUtils. The vendor’s example line is:

ERROR upgrade.base.ReflectionUtils ... Failed to load allResourceFiles map from
/opt/CPupgrade-tools-../../../../tmp/<dir>/scripts/upgrade_files.conf

That is trimmed from Check Point’s published example, with one directory name replaced. Reading it as security people, three things stand out. All of this is our inference, not Check Point’s explanation:

  1. The server builds a filesystem path from a request value. The prefix /opt/CPupgrade-tools- is followed by a string that carries ../ sequences. A path that is assembled from input and never checked for traversal is the textbook CWE-22 setup.
  2. The target is a scripts/upgrade_files.conf under an attacker-chosen directory in /tmp. That fits the vendor’s words “upload” and “execute a script from an arbitrary path”: get files into a writable directory, then point the upgrade-tooling code at them.
  3. The line is logged as an ERROR, meaning the load failed. So it records attempts that did not resolve to a real file. We think attempts that did resolve would not log the same line, though we can’t prove that from a log sample.

If point 3 is right, a clean result on this check for CVE-2026-93616 is weaker evidence than it looks. We come back to that in the hunting section.

CVE-2026-93616 log reading: Check Point's own example log line, annotated to show a request-built path with traversal sequences, an attacker-chosen directory in tmp, and an ERROR that records failed lookups, labeled as XHack inference
Reading Check Point’s published log sample: confirmed text versus our inference

Who Is Affected by CVE-2026-93616

You are exposed if you run one of these products on an affected release:

  • Security Management Server
  • Multi-Domain Security Management Server
  • Log Server
  • Multi-Domain Log Server
  • SmartEvent

Check Point lists these as not affected: Smart-1 Cloud (the fix is already applied), Check Point firewall appliances, and Spark Firewall.

The release matrix, from sk1000171:

ReleaseAffectedFixed in
R82.20With no Jumbo HotfixR82.20 Security Hotfix (TAR)
R82.10Jumbo Hotfix Take 44 or lowerTake 45 or higher
R82Jumbo Hotfix Take 126 or lowerTake 127 or higher
R81.20Jumbo Hotfix Take 166 or lowerTake 170 or higher
R81.10 (end of support)Jumbo Hotfix Take 190 or lowerTake 192 or higher
R81, R80.40, R80.30, R80.20, R80.10, R80 (all end of support)AffectedNo fix named in the advisory

Two details are easy to miss. First, Check Point states that LivePatch Take 28/29 does not address this issue, and says the nature of the fix rules out a LivePatch altogether. Second, the advisory names no fix for the release families that are already end of support. Our reading is that those systems need to move to a supported release, but the advisory does not spell out that path, so confirm it with Check Point support.

How to Fix CVE-2026-93616

Work through these in order to close CVE-2026-93616:

  1. Install the fix for your release. Use the R82.20 Security Hotfix, or a Jumbo Hotfix Accumulator at the take numbers in the table. Those accumulators also include the fix for CVE-2026-91843, covered below.
  2. If you can’t patch today, restrict access. Check Point’s mitigation is to keep management servers behind a Check Point gateway and make sure TCP/19009 is reachable only from trusted IP addresses. In SmartConsole, edit the entry under Manage & Settings, then Permissions & Administrators, then Trusted Clients.
  3. Hunt before you call it closed. Run the two checks below on every management and log server, because exploitation began before the fix existed.
  4. Treat end-of-support management servers as the urgent ones. They have no named fix, so network restriction is the control you have right now.

A note on the port. The advisory restricts TCP/19009 but does not say what listens there. Check Point community port lists describe 19009 as the CPM web-service port used between the management GUI and the server. Those pages blocked our automated fetch, so we’re relaying that from search snippets, not from a page we read. Verify it against your own hardening guide.

Hunting for CVE-2026-93616 Exploitation

Check Point gives two indicators for CVE-2026-93616. Run both from Expert mode on each Security Management, Multi-Domain, Log, Multi-Domain Log, and SmartEvent server. These commands are Check Point’s, shortened here:

# Indicator 1: logins with an extremely long username (1,001+ characters)
grep -nHP "login\(loginRequest=LoginRequest\{authenticationInfo=AuthenticationInfoBase\{username='[^' ]{1001,}'" "$MDS_FWDIR"/log/cpm.elg*

# If that matches, look for an fwm or mds core dump from the same time
ls -l /var/log/dump/usermode/ | grep -e fwm -e mds

# Indicator 2: the ReflectionUtils error with traversal sequences in the path
grep -E "ERROR.*upgrade\.base\.ReflectionUtils.*Failed to load allResourceFiles map from" $MDS_FWDIR/log/cpm.elg*

What each result means, per Check Point:

  • Indicator 1 plus a matching core dump: “a potential attempt to exploit this vulnerability.”
  • Indicator 2 with ../ in the path: a potential attempt to exploit this CVE. Review the output for traversal sequences.

Our caveats, labeled as such:

  • Indicator 1 looks like a different bug. An overlong username that crashes the login process resembles a stack overflow, and the same hotfix fixes CVE-2026-91843, which NVD describes as “a stack overflow during the unauthenticated login process.” Check Point lists the indicator under CVE-2026-93616, so run it either way, but don’t be surprised if a hit relates to the neighbor.
  • Log retention limits what you can see. The first observed attack was July 23. Whether cpm.elg* files that old still exist on your servers depends on rotation, so a clean grep may mean the evidence is gone.
  • Point 3 above applies. If failed lookups are what gets logged, a successful attempt may leave a different trace.

If you find a match, preserve logs and any available disk or memory evidence before you patch or reboot, consistent with CISA’s forensic-triage flag on this entry.

The Other Half of the CVE-2026-93616 Advisory: CVE-2026-85102 and Check Point’s 2026 KEV Run

Check Point’s blog advisory covers two bugs together, and CISA added both on September 22.

CVE-2026-85102 is a different component. It is a pre-authentication remote code execution flaw in the Security Gateway’s VPN certificate handling (NVD lists CWE-295, improper certificate validation), CVSS 9.8, affecting Security Gateway and Spark Firewall. Check Point fixed it on September 9 and later reported exploitation attempts from September 12, using certificates with subjects such as CN=vpn,OU=users,O=global, from anonymization infrastructure. Check Point says the list of subjects is not exhaustive. Its advisory sk1000117 would be the primary source for that bug, but the page did not render for our automated fetch, so we relied on the NVD record and Check Point’s blog.

The KEV catalog itself shows how often this vendor appears. Counting directly from the CISA JSON, Check Point has five entries: CVE-2024-24919 in May 2024, then four in 2026: CVE-2026-50751 (Security Gateway, June 8), CVE-2026-16232 (SmartConsole, July 22), and the two from September 22. We are not drawing a conclusion about why. The count is just what the catalog says.

How XHack Reads CVE-2026-93616

The lesson from CVE-2026-93616 that applies on your network, whatever you run, is an exposure question: which networks can reach your management interfaces, and does that match what you believe?

Check Point’s own mitigation is a trusted-clients list on TCP/19009. That is only as good as the list, and lists drift. A management port that was meant for three administrator workstations tends to end up reachable from a jump host, a VPN pool, or a flat network segment nobody revisited.

That is testable. Our AI VAPT services work includes checking whether management and administration services are reachable from segments that should never see them, and whether the answer changed since the last review. Our write-ups on CVE-2026-76504 in Cisco’s SD-WAN Manager and CVE-2026-94127 in F5 BIG-IP ask the same question about two other control planes. Note that XHack tests and reports on exposure, and a pentest report does not certify that a system is free of a given vulnerability.

If you run Check Point, patching CVE-2026-93616 comes first, then the hunt, then a review of who can reach 19009.

FAQ: CVE-2026-93616 Questions Answered

What is CVE-2026-93616?

CVE-2026-93616 is a CVSS 9.8 directory traversal and file upload vulnerability in Check Point’s management web service. It lets an unauthenticated attacker upload and execute arbitrary scripts on a Check Point Management Server.

Is CVE-2026-93616 being exploited?

Yes. Check Point says it is exploited in the wild and knows of a handful of attacked customers. Check Point Research saw targeted attacks on July 23, 2026, almost two months before the September 22 fix. CISA added it to KEV on September 22.

Which Check Point products does CVE-2026-93616 affect?

Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Smart-1 Cloud, firewall appliances, and Spark Firewall are listed as not affected.

How do I fix CVE-2026-93616?

Install the R82.20 Security Hotfix or a Jumbo Hotfix at Take 45 (R82.10), 127 (R82), 170 (R81.20) or 192 (R81.10) or higher. LivePatch does not address it. If you can’t patch yet, restrict TCP/19009 to trusted IP addresses.

How do I check whether CVE-2026-93616 was used against me?

Run Check Point’s two grep checks against cpm.elg* on every management and log server, and check for fwm or mds core dumps at the same time as any long-username login. A clean result is weaker evidence if your logs have rotated.

Does CVE-2026-93616 affect Check Point firewalls?

Not directly. Check Point lists firewall appliances as not affected by this CVE. The separate bug CVE-2026-85102 does affect Security Gateway and Spark Firewall VPN, and was fixed on September 9.

The Bottom Line

CVE-2026-93616 was used in targeted attacks 61 days before anyone outside Check Point could patch it, and it targets the system that holds the policy for your firewalls. Install the fix for your release, restrict TCP/19009 until you have, and run both indicator checks with the caveat that rotated logs may hide the evidence.

If a management server is end of support with no named fix, put it first on the list. A clean grep today doesn’t tell you what happened in July.


Categories

News

Previous

Bug Bounty vs Freelance Pentesting: Which Pays Better in 2026?

Next

Why the curl Bug Bounty Ended in 2026: The Truth and What Came Next

On this page

Why the Server Behind CVE-2026-93616 Is the Prize

What CVE-2026-93616 Is, According to Check Point

The 61-Day Gap Behind CVE-2026-93616

What Check Point’s Log Sample Says About the CVE-2026-93616 Mechanism

Who Is Affected by CVE-2026-93616

How to Fix CVE-2026-93616

Hunting for CVE-2026-93616 Exploitation

The Other Half of the CVE-2026-93616 Advisory: CVE-2026-85102 and Check Point’s 2026 KEV Run

How XHack Reads CVE-2026-93616

FAQ: CVE-2026-93616 Questions Answered

What is CVE-2026-93616?

Is CVE-2026-93616 being exploited?

Which Check Point products does CVE-2026-93616 affect?

How do I fix CVE-2026-93616?

How do I check whether CVE-2026-93616 was used against me?

Does CVE-2026-93616 affect Check Point firewalls?

The Bottom Line

Related articles

Continue reading

CVE-2026-76461: The Critical Cisco Email Gateway Bug Triggered by One Email

News

CVE-2026-76461: The Critical Cisco Email Gateway Bug Triggered by One Email

CVE-2026-76461 is a CVSS 9.8 SQL injection in Cisco Secure Email Gateway, exploited in the wild. Affected builds, fixes,...

Read article
CVE-2026-82042: The Critical UTMStack Flaw Where One Shared Key Was Admin

News

CVE-2026-82042: The Critical UTMStack Flaw Where One Shared Key Was Admin

CVE-2026-82042 and CVE-2026-82041 are critical UTMStack SIEM flaws: one shared key acted as admin, and no role check gua...

Read article
CVE-2026-102489: How a Critical Zammad Chain Gave an Attacker Root in Seconds

News

CVE-2026-102489: How a Critical Zammad Chain Gave an Attacker Root in Seconds

CVE-2026-102489 and CVE-2026-102490 chain a Zammad session hijack into root, and CISA says both are exploited. What̵...

Read article