Vulnerability
Published 2026-09-22
Verified 2026-09-27

Check Point Management Server CVE-2026-93616 (CVSS 9.8) path-traversal upload RCE — exploited in the wild

Check Point sk1000171 (approved/created 20 September 2026; last modified 22 September 2026; CVE published 22 Sep) documents CVE-2026-93616: directory traversal plus file upload lets an unauthenticated attacker upload and execute arbitrary scripts on Quantum Security Management / Multi-Domain / Log Server / Multi-Domain Log Server / SmartEvent. Check Point CVSS 3.1 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); CWE-22. Vendor states the vulnerability is exploited in the wild and a handful of customers have been attacked. Smart-1 Cloud already patched; firewall appliances / Spark not affected. LivePatch Take 28/29 does not fix this issue (no LivePatch for this fix). Distinct from desk CVE-2026-91843 (login stack overflow; same Jumbo trains also pick that up). Primary: Check Point sk1000171; metadata: CVE.report; wire: BleepingComputer 22 Sep 2026.

Product
Check Point Quantum Security Management Server, Multi-Domain Security Management, Log Server, Multi-Domain Log Server, SmartEvent (not Smart-1 Cloud / firewall appliances / Spark)
Versions
Affected: R82.20 (no Jumbo); R82.10 Jumbo Take ≤44; R82 Jumbo Take ≤126; R81.20 Jumbo Take ≤166; R81.10 Jumbo Take ≤190 (EoS); R80/R80.10/R80.20/R80.30/R80.40/R81 (EoS). Fixes: R82.20 Security Hotfix (TAR); R82.10 Jumbo ≥Take 45; R82 Jumbo ≥Take 127; R81.20 Jumbo ≥Take 170; R81.10 Jumbo ≥Take 192. LivePatch Take 28/29 does not address this CVE.
CVSS
(CVSS 3.1 Critical; Check Point)
Exploited in Australia?
unknown
Patch to
Apply R82.20 Security Hotfix or matching Jumbo Hotfix Accumulator takes (≥45 / ≥127 / ≥170 / ≥192); until patched, place management behind a gateway and restrict TCP/19009 and Trusted Clients to trusted IPs per sk1000171; hunt IoCs in vendor advisory; do not rely on LivePatch Take 28/29 for this issue

Primary: Check Point sk1000171 — CVE-2026-93616 Management Server path traversal (22 Sep 2026) · Vendor: Check Point — sk1000171 · CVE: CVE-2026-93616, CVE-2026-91843 · CVE.report — CVE-2026-93616; also BleepingComputer 22 Sep 2026

vulnerabilities network identity