Check Point Management Server directory traversal/file upload zero-day (CVE-2026-93616)
Vulnerability
Summary
Hide ▲
Show ▼
Check Point issued urgent fixes for CVE-2026-93616, a critical zero-day in Management Server products that is being exploited in the wild. The flaw is a directory traversal and file upload issue that can let unauthenticated attackers upload and execute arbitrary scripts on affected servers. Impacted products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Check Point said it is aware of a handful of customers who have been attacked.
Related Happenings
Check Point Security Management and Log Servers stack overflow security flaw (CVE-2026-91843)
Vulnerability
H score46
First: 17.09.2026 21:08
Last: 17.09.2026 21:08
Sources 1
About this happening:
Check Point Security Management Server and Log Server deployments are affected by CVE-2026-91843, a critical stack-based buffer overflow in the login process that...
Check Point Security Management and Log Servers stack overflow security flaw (CVE-2026-91843)
VulnerabilityAbout this happening: Check Point Security Management Server and Log Server deployments are affected by CVE-2026-91843, a critical stack-based buffer overflow in the login process that...
Latest development: 18.09.2026 03:00
Check Point confirms that R82.20, standalone deployments, Log Servers, and Multi-Domain servers are vulnerable, and says customers who need fixes for out-of-support versions should open a ticket with Check Point support.
Check Point Security Gateways and Security Management Server VPN certificate flaws (multiple vulnerabilities)
Vulnerability
H score53
First: 10.09.2026 14:45
Last: 10.09.2026 14:45
Sources 1
About this happening:
Check Point Security Gateways and Security Management Server are affected by two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that can let an...
Check Point Security Gateways and Security Management Server VPN certificate flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Check Point Security Gateways and Security Management Server are affected by two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that can let an...
Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India
Campaign
H score22
First: 12.08.2026 16:35
Last: 12.08.2026 16:35
Sources 1
About this happening:
Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India,...
Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India
CampaignAbout this happening: Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India,...
Latest development: 12.08.2026 18:38
Lazarus broadened the Operation Dream Job campaign against defense, aerospace, and aviation organizations in Europe and India by using fraudulent recruitment offers, with successful targeting also observed in Western Europe, including France and Germany, and activity extending into South America, including Brazil. Check Point also tied the latest wave to the Troy backdoor, a FudModule variant with a CVE-2026-68820 exploit, and compromised Roundcube instances used to hide malicious communications and deploy the RelayShell web shell.
CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)
Exploitation Wave
H score89
First: 04.05.2026 11:25
Last: 04.05.2026 11:25
Sources 1
About this happening:
CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...
CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)
Exploitation WaveAbout this happening: CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/Mitigation
H score46
First: 20.02.2026 19:02
Last: 20.02.2026 19:02
Sources 1
About this happening:
CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/MitigationAbout this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
Timeline
-
23.09.2026 09:14 2 articles · 0h ago
Check Point warns of exploited CVE-2026-93616 in Management Server
Initial DisclosureCheck Point announced urgent patches for CVE-2026-93616, a critical directory traversal and file upload flaw in Management Server products that can let unauthenticated attackers upload and execute arbitrary scripts. The company said the vulnerability is being exploited in the wild and that it is aware of a handful of customers who have been attacked.
Show sources
- Check Point Patches Exploited Management Server Zero-Day — www.securityweek.com — 23.09.2026 09:14
- Check Point Patches Exploited Management Server Zero-Day — www.securityweek.com — 23.09.2026 09:14
-
23.09.2026 09:14 1 articles · 0h ago
Check Point releases hotfixes and IoCs for CVE-2026-93616
Mitigation Patch UpdateCheck Point released the R82.20 Security Hotfix (TAR) and included fixes for CVE-2026-93616 in the Jumbo Hotfix Accumulator for R82.10 (Take 45), R82 (Take 127), R81.20 (Take 170), and R81.10 (Take 192). The company also released indicators of compromise (IoCs), warned that standard LivePatch updates do not resolve CVE-2026-93616, and advised customers to restrict Management Server access behind a security gateway or firewall and limit TCP/19009 to trusted IP addresses.
Show sources
- Check Point Patches Exploited Management Server Zero-Day — www.securityweek.com — 23.09.2026 09:14