CVE-2026-93616

Published Sep 22, 2026

Last updated 12 hours ago

Exploit knownCVSS critical 9.8
Network
Zero-day
Supply chain
VPN

Overview

Description
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
Source
cve@checkpoint.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Check Point Multiple Products Path Traversal Vulnerability
Exploit added on
Sep 22, 2026
Exploit action due
Sep 25, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

cve@checkpoint.com
CWE-22

Social media

Hype score
Not currently trending
  1. 🚨 ALERT — ACTIVELY EXPLOITED CHECK POINT FLAWS DATE: September 22, 2026 CONFIRMED BY: Check Point Research / CISA PRODUCT: Check Point Security Management / Security Gateway / Spark Firewall CVEs: CVE-2026-93616, CVE-2026-85102 IMPACT: CVE-2026-93616 is a pre-authenticat

    @Python_s_

    23 Sept 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Check Point: active exploitation of Management pre-auth path traversal (CVE-2026-93616) and Spark/gateway cert RCE path (CVE-2026-85102). Handful of Mgmt hits confirmed; Spark probes global. Emergency fixes live; CISA KEV due Sep 25. Restrict Mgmt to trusted IPs.

    @richtechguy

    23 Sept 2026

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🐦 🚨 Active exploitation alert: F5 BIG-IP APM RCE (CVE-2026-94127, CVSS 9.8) and Check Point mgmt-server path traversal (CVE-2026-93616) exploited in the wild — patch now. Also on CISA KEV: Arista VeloCloud Orchestrator (CVSS 10.0). #infosec #CVE #0day

    @ita_ipo

    23 Sept 2026

    65 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Patch Now | September 23, 2026 Bringing these vulnerabilities to your attention: - Zyxel GS1900 switches (CVE-2026-7273) - Check Point Security Management (CVE-2026-93616, CVSS 9.8) - Veeam Agent for Windows (CVE-2026-32996) https://t.co/fR71dyoG2H | #CyberSafeUG #CERTUGCC htt

    @CERT_UG

    23 Sept 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Le plan de management, c’est souvent le maillon qu’on oublie. Check Point: faille pré-auth sur Security Management (CVE-2026-93616), exploitation limitée, patch dispo. Aussi exploitation active côté VPN gateway (CVE-2026-85102). À patcher vite. https://t.co/01rHqrdUHC

    @kamel_laimene

    23 Sept 2026

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. F5 BIG-IP APM, Check Point Security Gateway und VeloCloud Orchestrator stehen wegen aktiv ausgenutzter Sicherheitslücken im Fokus. Ein Überblick über CVE-2026-94127, CVE-2026-85102, CVE-2026-93616 und CVE-2026-93952. https://t.co/UIVtmEjfy1

    @oliverjessner

    23 Sept 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Urgent if you run Check Point Security Management or Spark: CVE-2026-93616 is now confirmed exploited in the wild. A path-traversal flaw in the Management web service enables unauthenticated script execution without login. Many versions are affected and LivePatch Takes 28/29 do h

    @dailytechonx

    23 Sept 2026

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. #Check Point released Security Advisory on active exploitation of #CVE-2026-85102 and a Management Pre-Authentication #Zero-day Vulnerability #CVE-2026-93616. Apply updates to remain safe. https://t.co/m4D30qLdLZ

    @NCIIPC

    23 Sept 2026

    230 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 👉 Check Point'te CVSS 9.8'lik iki kritik açık için yama var ama tehdit sürüyor. VPN sertifika açığında (CVE-2026-85102) saldırılar hâlâ devam ediyor. Yönetim sunucusu zero-day'inde (CVE-2026-93616) LivePatch yetmiyor, ayrı hotfix şart. #CheckPoint #ZeroDay #

    @trsiberyazilim

    23 Sept 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Check Point warns of active zero-day exploitation in Security Management Servers (CVE-2026-93616) & gateways (CVE-2026-85102). Hunt for rogue cert subjects CN=vpn / CN=vpn-user. Details: https://t.co/q6Lxi6sc56 https://t.co/QC14eBVf0C #2workly

    @2Workly

    23 Sept 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Critical zero-days in Cisco ISE (CVE-2026-76460) & Check Point Management (CVE-2026-93616) allow unauth access & RCE. Immediate patching is vital to safeguard data privacy/integrity in transit. #Cybersecurity #ZeroDay #News

    @YourAnon_irc

    23 Sept 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Check Point: since Sep 12 attackers have been sending Spark firewalls a VPN certificate with subject CN=vpn. Unpatched gateways run their code (CVE-2026-85102, CVSS 9.8, fix out Sep 9). Plus a mgmt server zero-day, CVE-2026-93616, exploited since July. KEV due Sep 25. #MSP https:

    @vkhoetsyan

    23 Sept 2026

    69 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  13. 🚨 Actively Exploited CVE-2026-93616 in Check Point Security Management Server Allows Unauthenticated Script Execution Critical Vulnerability Alert! Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and

    @zoomeyebot

    23 Sept 2026

    16 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  14. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。Check Point複数製品のCVE-2026-85102+CVE-2026-93616、Arista VeloCloud OrchestratorのCVE-2026-93952、F5 BIG-IP APMのCVE-20

    @__kokumoto

    23 Sept 2026

    689 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  15. Check Point confirms active exploitation of CVE-2026-85102: a CVSS 9.8 pre-auth RCE in VPN certificate validation. Patch shipped Sep 9, attacks began Sep 12. A second flaw, CVE-2026-93616, hits Security Management. Three days from fix to attack. https://t.co/hDp57SUr5k https://t.

    @aratech_social

    23 Sept 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Check Point reports active exploitation of CVE-2026-85102, a pre-auth RCE in Security Gateway VPN certificate handling, and limited exploitation of zero-day CVE-2026-93616 in Management. Fixes are available; customers should patch now. https://t.co/M16SuBdQQs #CyberSecurity

    @xboxnaman

    23 Sept 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Check Point $CHKP reports exploitation of CVE-2026-85102 and CVE-2026-93616. Canada's Cyber Centre says CISA added both to its exploited-vulnerabilities catalog on September 22. AI-generated illustrative visuals. https://t.co/LO6Hkpr7yu

    @ShortInfoNews

    23 Sept 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🔒 #CyberSecurity CVE-2026-93616: Check Point Management Server Path Traversal Actively Exploited… "On September 22, 2026, CISA added CVE-2026-93616 to the Known Exploited…" 🔗 https://t.co/kM8zGwUswg #CyberSecurity #ThreatIntel #cve202693616 #critical #cisakev

    @SecurityAr58409

    23 Sept 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. استغلال نشط لثغرتين يتطلب مراجعة أمنية فورية. التحذير الأمني يشير إلى CVE-2026-85102 وثغرة Management Pre-Authentication برقم CVE-2026-93616، ما يعني أن الخطر لا يقتصر على وجود الث

    @fad_777

    22 Sept 2026

    49 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Check Point mgmt servers hit by unauth script-exec flaw. CVE-2026-93616 CVSS 9.8; hotfix out. Check Point + BleepingComputer. Verify independently. #CyberSecurity #InfoSec #ZeroDay #CVE #ThreatIntel

    @ThreatAlis

    22 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes