NewsTradingSentimentEventsCommunityBriefing
Tech

Check Point Patches Zero-Day Exploited in Live Attacks

By Tech Desk · · 2 min read
A server rack with blinking status lights in a dark room

Emergency hotfixes address a critical flaw allowing unauthenticated script execution on enterprise security servers.

Key points

  • Check Point released emergency hotfixes for CVE-2026-93616, a critical flaw allowing unauthenticated script execution on management servers.
  • The company confirmed the vulnerability is being actively exploited in the wild, affecting a small number of enterprise customers.
  • Administrators are advised to apply the R82.20 Security Hotfix or isolate systems behind firewalls and restrict access to trusted IPs as a temporary measure.

Check Point Software has released emergency updates to address a critical vulnerability in its Security Management Server. The flaw, tracked as CVE-2026-93616, allows attackers to upload and run arbitrary scripts without authentication. BleepingComputer reports that the company has confirmed this weakness is currently being exploited in the wild, affecting a small number of customers.

The Security Management Server acts as the central hub for enterprise security policies, storing configurations and processing administrator changes. Because it holds the keys to the network’s security posture, a compromise here allows threat actors to bypass controls and execute malicious code across the system. The attack requires low complexity, making it an attractive target for automated or opportunistic cybercriminals.

Critical flaw enables remote script execution

The vulnerability is a path traversal flaw, a type of error that has long been considered a basic failure in software security. U.S. regulators, including CISA and the FBI, have repeatedly warned companies to eliminate such weaknesses before release, noting they have been deemed unforgivable since 2007. Despite these warnings, the flaw allowed unauthenticated users to bypass intended directory restrictions and place executable scripts on the server.

Check Point has confirmed that the issue affects several core products, including the Multi-Domain Security Management Server, Log Server, and SmartEvent. The company advises security teams to immediately check their networks for signs of intrusion using the specific indicators of compromise shared in their advisory. This is not a theoretical risk; the vendor has acknowledged active exploitation by a handful of attackers.

Immediate mitigation steps for administrators

For organizations that cannot deploy the R82.20 Security Hotfix immediately, Check Point offers temporary mitigation measures. The primary recommendation is to isolate the vulnerable systems by placing them behind a firewall. Additionally, administrators should restrict access to the management interface by limiting connections to trusted IP addresses. This can be configured through the SmartConsole dashboard under the permissions and administrators settings.

These steps reduce the attack surface by ensuring that only known, internal systems can communicate with the management server. However, this is a stopgap, not a permanent fix. The underlying code vulnerability remains until the hotfix is applied, leaving the system exposed to new exploitation techniques if the network perimeter is breached.

Pattern of recent security failures

This incident is part of a concerning trend of active exploitation against Check Point products. In recent months, other critical flaws have been abused by ransomware gangs and state-aligned actors. For example, a vulnerability in Quantum Security Gateways was linked to NailaoLocker ransomware, while a separate authentication bypass has been exploited by Qilin ransomware affiliates since June.

Dutch security authorities recently warned organizations to urgently patch two critical VPN flaws, citing expected imminent exploitation attempts. More recently, another authentication bypass allowing root-level access was patched. The repeated occurrence of these issues highlights a persistent challenge in the vendor’s security posture, demanding that customers maintain a higher level of vigilance and rapid patching discipline to protect their infrastructure.

Based on reporting by BleepingComputer, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories