CVE Tools

Check Point warns of Management Server zero-day exploited in attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedCheck Point Security Management ServerCheck Point Multi-Domain Security Management Server

Our summary

Check Point has released R82.20 Security Hotfix for CVE-2026-93616, an actively exploited path traversal vulnerability affecting Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Unauthenticated attackers can upload and run arbitrary scripts, so organizations should apply the hotfix, review indicators of compromise, and restrict management access to trusted IP addresses where immediate patching is not possible.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store