CVE-2026-93616
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
- Published Sep 22, 2026
- CVSS 9.8 critical
- 19.7% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A fix is available
Affected software
In the news
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes The Hacker News ·
- ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats The Hacker News ·
- Vulnerability in Check Point Security Management Server CERT-FR ·
- Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks The Hacker News ·
- CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA ·
- Check Point security advisory (AV26-902) – Update 2 Canadian Centre for Cyber Security ·