Check Point warns of Management Server zero-day exploited in attacks

Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts.
The Security Management Server is a central repository that stores and manages security policies, processes administrator changes, and collects system logs across enterprise networks.
Tracked as CVE-2026-93616, this path traversal flaw lets unauthenticated threat actors upload arbitrary scripts on vulnerable Check Point Management Servers and execute them in low-complexity attacks.
The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have urged software companies since May 2024 to remove path traversal weaknesses from their products before shipping, saying such security issues "have been called 'unforgivable' since at least 2007."
Check Point has addressed the vulnerability in R82.20 Security Hotfix and said that the complete list of affected products includes Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
"This vulnerability is exploited in the wild. Check Point is aware of a handful of customers who have been attacked," the company warned, while advising security teams to check their networks for evidence of successful exploitation using the indicators of compromise shared in this security advisory.
In a separate advisory, Check Point VP of Research Lotem Finkelstein said the attacks started on September 12, when the company observed a wave of exploitation attempts targeting Spark customers.
Check Point also provides temporary mitigation measures for customers who can't immediately deploy the hotfix on vulnerable systems, including hardening vulnerable systems against attacks by placing them behind a firewall and limiting access to trusted IP addresses from Manage & Settings > Permissions & Administrators > Trusted Clients in the SmartConsole dashboard.
Editing Trusted Clients rules in SmartConsole (Check Point Software)In recent months, Check Point has warned customers that other flaws were being actively exploited in the wild.
For instance, two years ago, CISA flagged a flaw (CVE-2024-24919) in Check Point's Quantum Security Gateways as actively exploited by ransomware gangs, confirming an Orange Cyberdefense CERT report linking these attacks to NailaoLocker ransomware.
Qilin ransomware affiliate has also exploited an authentication bypass (CVE-2026-50751) zero-day since June, while a second auth bypass zero-day (CVE-2026-16232) has been exploited since at least July to authenticate with administrator privileges to SmartConsole admin panels.
Two weeks ago, the Dutch National Cyber Security Centre (NCSC-NL) also warned organizations to urgently patch two critical Check Point VPN flaws (CVE-2026-85102 and CVE-2026-85103) because it "expects exploitation attempts to occur soon."
More recently, on Friday, Check Point released security updates to address another critical authentication bypass (CVE-2026-16232) in the login process for Security Management Server and Security Gateways that lets attackers execute code with root privileges on management systems.
While the company has not yet flagged CVE-2026-16232 as actively exploited, it said security teams can identify attacks by looking for "Administrator failed to log in: Username too long" alerts in the Audit and Admin login logs.
References in this story
- NVD - Home nvd.nist.gov
- CISA urges software devs to weed out path traversal vulnerabilities www.bleepingcomputer.com CISA and the FBI urged software companies today to review their products and eliminate path traversal security vulnerabilities before shipping.
- support.checkpoint.com
- support.checkpoint.com
- Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication… blog.checkpoint.com As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements for our %
- Introduction sc1.checkpoint.com This document provides practical hardening recommendations for Check Point Security Gateways and Management Servers running supported Gaia OS releases. The recommendations apply to these versions: ...
- Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…
- Check Point links VPN zero-day attacks to Qilin ransomware gang www.bleepingcomputer.com Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks.
- Check Point warns of SmartConsole zero-day exploited in attacks www.bleepingcomputer.com Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
- Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent www.bleepingcomputer.com The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
- New Check Point flaw lets hackers execute code with root privileges www.bleepingcomputer.com Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems.
- sk185169 - CVE-2026-16232 - Authentication bypass with SmartConsole login process using application token support.checkpoint.com Applies to: Multi-Domain Security Management, Security Management



