← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 22, 2026 · 19:31via Security Affairs

Check Point Fixes a New Actively Exploited Critical Security Flaw

Brief

Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers.

Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. The security firm bug is already being exploited. Attackers can abuse the flaw without logging in to upload malicious scripts and execute them on vulnerable servers.

Because the Management Server controls security policies, admin activity and system logs across Check Point deployments, a compromise could have a wider impact on an enterprise network.

The vulnerability affects more than Check Point’s main Security Management Server. The impacted products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.

Read more on Security Affairs