Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts.
The Security Management Server is a central repository that stores and manages security policies, processes administrator changes, and collects system logs across enterprise networks.
Tracked as CVE-2026-93616, this path traversal flaw lets unauthenticated threat actors upload arbitrary scripts on vulnerable Check Point Management Servers and execute them in low-complexity attacks.
The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have urged software companies since May 2024 to remove path traversal weaknesses from their products before shipping, saying such security issues “have been called ‘unforgivable’ since at least 2007.”
Check Point has addressed the vulnerability in R82.20 Security Hotfix and said that the complete list of affected products includes Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
“This vulnerability is exploited in the wild. Check Point is aware of a handful of customers who have been attacked,” the company warned, while advising security teams to check their networks for evidence of successful exploitation using the indicators of compromise shared in this security advisory.
In a separate advisory, Check Point VP of Research Lotem Finkelstein said the attacks started on September 12, when the company observed a wave of exploitation attempts targeting Spark customers.
Check Point also provides temporary mitigation measures for customers who can’t immediately deploy the hotfix on vulnerable systems, including hardening vulnerable systems against attacks by placing them behind a firewall and limiting access to trusted IP addresses from Manage & Settings > Permissions & Administrators > Trusted Clients in the SmartConsole dashboard.
In recent months, Check Point has warned customers that other flaws were being actively exploited in the wild.
For instance, two years ago, CISA flagged a flaw (CVE-2024-24919) in Check Point’s Quantum Security Gateways as actively exploited by ransomware gangs, confirming an Orange Cyberdefense CERT report linking these attacks to NailaoLocker ransomware.
Qilin ransomware affiliate has also exploited an authentication bypass (CVE-2026-50751) zero-day since June, while a second auth bypass zero-day (CVE-2026-16232) has been exploited since at least July to authenticate with administrator privileges to SmartConsole admin panels.
Two weeks ago, the Dutch National Cyber Security Centre (NCSC-NL) also warned organizations to urgently patch two critical Check Point VPN flaws (CVE-2026-85102 and CVE-2026-85103) because it “expects exploitation attempts to occur soon.”
More recently, on Friday, Check Point released security updates to address another critical authentication bypass (CVE-2026-16232) in the login process for Security Management Server and Security Gateways that lets attackers execute code with root privileges on management systems.
While the company has not yet flagged CVE-2026-16232 as actively exploited, it said security teams can identify attacks by looking for “Administrator failed to log in: Username too long” alerts in the Audit and Admin login logs.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Check Point warns of SmartConsole zero-day exploited in attacks
Cisco warns of max severity ISE zero-day exploited in attacks
Google fixes actively exploited Android zero-day on Pixel devices
Cisco patches Secure Email Gateway zero-day exploited in attacks
CISA: Hackers now exploit max severity GitLab flaw in attacks
Researchers escape OpenAI Codex sandbox to run commands on host
Malicious npm packages evade install-script defenses at runtime
Microsoft reminds admins to migrate Entra ID users to passkeys
Build cyber resilience with Wazuh: The open-source SIEM & XDR for proactive protection
Automate Onboarding and Access Reviews with No-Code IGA: See how it works
Overdue a password health-check? Audit your Active Directory for free
Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.
Overdue a password health-check? Audit your Active Directory for free
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



