Check Point has disclosed CVE-2026-93616, a critical CVSS 9.8 path-traversal and unsafe file-upload vulnerability affecting its Security Management infrastructure. An unauthenticated remote attacker can upload and execute arbitrary scripts and load arbitrary Java classes, enabling remote code execution. Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
The company confirmed that the flaw was exploited in a small number of targeted attacks before fixes were available, though it has not identified the threat actor, victims, or objectives. Organizations should immediately deploy the R82.20 Security Hotfix or applicable fixed Jumbo Hotfix Accumulator, review Check Point-provided indicators and relevant logs/core dumps, and restrict management access—including TCP/19009—to trusted systems; where patching is delayed, SmartConsole Trusted Clients and firewall rules should limit access to approved IP addresses.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Check Point updated its CVE-2026-93616 advisory with indicators and guidance for investigating potentially affected management, logging, and SmartEvent servers, including cpm.elg logs and FWM or MDS core dumps.
Check Point observed a handful of targeted customer attacks exploiting CVE-2026-93616 before a security update was available. The activity was not publicly attributed, and affected organizations and attacker objectives were not disclosed.
Check Point disclosed CVE-2026-93616, a critical path-traversal and unsafe file-upload flaw that allows unauthenticated attackers to upload and execute arbitrary scripts on vulnerable Security Management infrastructure. The company released an R82.20 Security Hotfix and fixed Jumbo Hotfix Accumulator versions, and advised affected customers to restrict management access while remediation is pending.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.