Check Point disclosed CVE-2026-93616, a critical pre-authentication path traversal vulnerability in Security Management Server that the company says was used in a small number of targeted attacks in July. A separate VPN issue, CVE-2026-85102, has also drawn exploitation attempts against Spark firewall customers.

Exposure and impact

CVE-2026-93616 can allow an attacker with access to the server’s web service to upload and execute scripts without logging in. The affected product is the management platform that controls policies for managed Check Point gateways, making rapid inventory and remediation important.

Defender actions

  • Check Security Management versions and Jumbo Hotfix takes against Check Point’s advisory.
  • Install the vendor fix listed in support article sk1000171.
  • Use the supplied hunting guidance and indicators to assess whether activity occurred before remediation.
  • For the VPN issue, confirm the September 9 fix is installed and review certificate-based Mobile Access activity.

Source: The Hacker News: Check Point management server advisory; linked Check Point and CVE records.

By Allan