Check Point warns of Management Server zero-day exploited in attacks
Check Point released emergency hotfixes for a critical Security Management Server flaw tracked as CVE-2026-93616. The path traversal bug lets unauthenticated attackers upload and execute arbitrary scripts, and the company says it is exploited in the wild.
- CVE-2026-93616 is a path traversal flaw in Security Management Server
- Allows unauthenticated upload and execution of arbitrary scripts
- Fixed in R82.20 Security Hotfix
- Check Point is aware of a handful of attacked customers
Read next
Security