
Table of contents
17
Read this in 30 seconds: CVE-2026-93616 is a CVSS 9.8 pre-authentication flaw in Check Point’s Security Management software, and Check Point says it was exploited as a zero-day.
- It was used for 61 days before a fix existed. Check Point Research saw “pinpointed” attacks on July 23, 2026. The fix and advisory landed September 22.
- No login is needed. A directory traversal and file upload bug in the management web service lets an unauthenticated attacker upload and run scripts on the server that controls your firewalls.
- A LivePatch will not save you. Check Point says LivePatch Take 28/29 does not address it. You need a Jumbo Hotfix take or the R82.20 security hotfix.
- The mitigation is network access control. Limit TCP/19009 to trusted IP addresses, then run Check Point’s two hunt checks on every management and log server.
- CISA flagged it for forensic triage. Added to KEV on September 22, due September 25, which was 11 days ago.
The box that writes the rules for your firewalls is not supposed to be the weak point, and CVE-2026-93616 is what it looks like when it is.
Check Point published advisory sk1000171 for CVE-2026-93616 on September 22, 2026. It says an unauthenticated attacker can upload and execute arbitrary scripts on a Check Point Management Server, that the bug is exploited in the wild, and that Check Point knows of “a handful of customers who have been attacked.”
This article walks through what the vendor confirms, what its own log sample reveals about how the bug works (clearly labeled as our reading), who is affected, and the exact checks to run today.

A Check Point Security Management Server is the system administrators use to define security policy and push it out to the gateways. Log Servers and SmartEvent collect and correlate what those gateways see. That role is general product knowledge, not something the advisory spells out, but it explains why this class of bug matters.
An attacker who gets code execution on a gateway controls one choke point. An attacker who lands it on the management server is sitting next to the policy, the administrator accounts, and the logs for every gateway it manages. That is our reasoning about the role, not a claim from Check Point about what the attackers did next. The advisory does not say what they did after the initial access.
CVE-2026-93616 affects exactly that tier: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. The gateways themselves are not the target here.
Check Point’s advisory sk1000171 describes CVE-2026-93616 as a directory traversal and file upload flaw that lets an unauthenticated attacker upload and run arbitrary scripts on the Management Server. The NVD record carries the same description, supplied by Check Point as the CNA.
The facts we can confirm from primary sources:
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The score in the NVD record comes from Check Point, not from NVD’s own analysts.Check Point has not named the targets or the attackers. The advisory pages we read name neither, and The Hacker News reports the same.
The dates matter more than usual here, because CVE-2026-93616 was a zero-day in the plain sense: attacks came first.
From July 23 to September 22 is 61 days, by our count. Check Point also reports the exploitation as a handful of targeted attacks, not mass scanning. That is the vendor’s characterization of what it saw, and it can only describe what Check Point itself observed.

Check Point has not published the request format or the vulnerable code for CVE-2026-93616, and this is closed-source software, so we can’t show you the bug. What it did publish is an indicator, and the example output in that indicator is informative.
The second indicator in sk1000171 tells you to search cpm.elg* for an error from upgrade.base.ReflectionUtils. The vendor’s example line is:
ERROR upgrade.base.ReflectionUtils ... Failed to load allResourceFiles map from
/opt/CPupgrade-tools-../../../../tmp/<dir>/scripts/upgrade_files.conf
That is trimmed from Check Point’s published example, with one directory name replaced. Reading it as security people, three things stand out. All of this is our inference, not Check Point’s explanation:
/opt/CPupgrade-tools- is followed by a string that carries ../ sequences. A path that is assembled from input and never checked for traversal is the textbook CWE-22 setup.scripts/upgrade_files.conf under an attacker-chosen directory in /tmp. That fits the vendor’s words “upload” and “execute a script from an arbitrary path”: get files into a writable directory, then point the upgrade-tooling code at them.If point 3 is right, a clean result on this check for CVE-2026-93616 is weaker evidence than it looks. We come back to that in the hunting section.

You are exposed if you run one of these products on an affected release:
Check Point lists these as not affected: Smart-1 Cloud (the fix is already applied), Check Point firewall appliances, and Spark Firewall.
The release matrix, from sk1000171:
| Release | Affected | Fixed in |
|---|---|---|
| R82.20 | With no Jumbo Hotfix | R82.20 Security Hotfix (TAR) |
| R82.10 | Jumbo Hotfix Take 44 or lower | Take 45 or higher |
| R82 | Jumbo Hotfix Take 126 or lower | Take 127 or higher |
| R81.20 | Jumbo Hotfix Take 166 or lower | Take 170 or higher |
| R81.10 (end of support) | Jumbo Hotfix Take 190 or lower | Take 192 or higher |
| R81, R80.40, R80.30, R80.20, R80.10, R80 (all end of support) | Affected | No fix named in the advisory |
Two details are easy to miss. First, Check Point states that LivePatch Take 28/29 does not address this issue, and says the nature of the fix rules out a LivePatch altogether. Second, the advisory names no fix for the release families that are already end of support. Our reading is that those systems need to move to a supported release, but the advisory does not spell out that path, so confirm it with Check Point support.
Work through these in order to close CVE-2026-93616:
A note on the port. The advisory restricts TCP/19009 but does not say what listens there. Check Point community port lists describe 19009 as the CPM web-service port used between the management GUI and the server. Those pages blocked our automated fetch, so we’re relaying that from search snippets, not from a page we read. Verify it against your own hardening guide.
Check Point gives two indicators for CVE-2026-93616. Run both from Expert mode on each Security Management, Multi-Domain, Log, Multi-Domain Log, and SmartEvent server. These commands are Check Point’s, shortened here:
# Indicator 1: logins with an extremely long username (1,001+ characters)
grep -nHP "login\(loginRequest=LoginRequest\{authenticationInfo=AuthenticationInfoBase\{username='[^' ]{1001,}'" "$MDS_FWDIR"/log/cpm.elg*
# If that matches, look for an fwm or mds core dump from the same time
ls -l /var/log/dump/usermode/ | grep -e fwm -e mds
# Indicator 2: the ReflectionUtils error with traversal sequences in the path
grep -E "ERROR.*upgrade\.base\.ReflectionUtils.*Failed to load allResourceFiles map from" $MDS_FWDIR/log/cpm.elg*
What each result means, per Check Point:
../ in the path: a potential attempt to exploit this CVE. Review the output for traversal sequences.Our caveats, labeled as such:
cpm.elg* files that old still exist on your servers depends on rotation, so a clean grep may mean the evidence is gone.If you find a match, preserve logs and any available disk or memory evidence before you patch or reboot, consistent with CISA’s forensic-triage flag on this entry.
Check Point’s blog advisory covers two bugs together, and CISA added both on September 22.
CVE-2026-85102 is a different component. It is a pre-authentication remote code execution flaw in the Security Gateway’s VPN certificate handling (NVD lists CWE-295, improper certificate validation), CVSS 9.8, affecting Security Gateway and Spark Firewall. Check Point fixed it on September 9 and later reported exploitation attempts from September 12, using certificates with subjects such as CN=vpn,OU=users,O=global, from anonymization infrastructure. Check Point says the list of subjects is not exhaustive. Its advisory sk1000117 would be the primary source for that bug, but the page did not render for our automated fetch, so we relied on the NVD record and Check Point’s blog.
The KEV catalog itself shows how often this vendor appears. Counting directly from the CISA JSON, Check Point has five entries: CVE-2024-24919 in May 2024, then four in 2026: CVE-2026-50751 (Security Gateway, June 8), CVE-2026-16232 (SmartConsole, July 22), and the two from September 22. We are not drawing a conclusion about why. The count is just what the catalog says.
The lesson from CVE-2026-93616 that applies on your network, whatever you run, is an exposure question: which networks can reach your management interfaces, and does that match what you believe?
Check Point’s own mitigation is a trusted-clients list on TCP/19009. That is only as good as the list, and lists drift. A management port that was meant for three administrator workstations tends to end up reachable from a jump host, a VPN pool, or a flat network segment nobody revisited.
That is testable. Our AI VAPT services work includes checking whether management and administration services are reachable from segments that should never see them, and whether the answer changed since the last review. Our write-ups on CVE-2026-76504 in Cisco’s SD-WAN Manager and CVE-2026-94127 in F5 BIG-IP ask the same question about two other control planes. Note that XHack tests and reports on exposure, and a pentest report does not certify that a system is free of a given vulnerability.
If you run Check Point, patching CVE-2026-93616 comes first, then the hunt, then a review of who can reach 19009.
CVE-2026-93616 is a CVSS 9.8 directory traversal and file upload vulnerability in Check Point’s management web service. It lets an unauthenticated attacker upload and execute arbitrary scripts on a Check Point Management Server.
Yes. Check Point says it is exploited in the wild and knows of a handful of attacked customers. Check Point Research saw targeted attacks on July 23, 2026, almost two months before the September 22 fix. CISA added it to KEV on September 22.
Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Smart-1 Cloud, firewall appliances, and Spark Firewall are listed as not affected.
Install the R82.20 Security Hotfix or a Jumbo Hotfix at Take 45 (R82.10), 127 (R82), 170 (R81.20) or 192 (R81.10) or higher. LivePatch does not address it. If you can’t patch yet, restrict TCP/19009 to trusted IP addresses.
Run Check Point’s two grep checks against cpm.elg* on every management and log server, and check for fwm or mds core dumps at the same time as any long-username login. A clean result is weaker evidence if your logs have rotated.
Not directly. Check Point lists firewall appliances as not affected by this CVE. The separate bug CVE-2026-85102 does affect Security Gateway and Spark Firewall VPN, and was fixed on September 9.
CVE-2026-93616 was used in targeted attacks 61 days before anyone outside Check Point could patch it, and it targets the system that holds the policy for your firewalls. Install the fix for your release, restrict TCP/19009 until you have, and run both indicator checks with the caveat that rotated logs may hide the evidence.
If a management server is end of support with no named fix, put it first on the list. A clean grep today doesn’t tell you what happened in July.
Categories
Related articles