Check Point warns of Management Server zero-day exploited in attacks
Reported exploitedCheck Point Security Management ServerCheck Point Multi-Domain Security Management ServerOur summary
Check Point has released R82.20 Security Hotfix for CVE-2026-93616, an actively exploited path traversal vulnerability affecting Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Unauthenticated attackers can upload and run arbitrary scripts, so organizations should apply the hotfix, review indicators of compromise, and restrict management access to trusted IP addresses where immediate patching is not possible.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.