Find notable cyber news and cases, enriched with sources, timelines, and signals.

Check Point Management Server directory traversal/file upload zero-day (CVE-2026-93616)

Vulnerability
First reported
Last updated
Happening score
H score 45
1 unique sources, 1 articles

Summary

Hide ▲

Check Point issued urgent fixes for CVE-2026-93616, a critical zero-day in Management Server products that is being exploited in the wild. The flaw is a directory traversal and file upload issue that can let unauthenticated attackers upload and execute arbitrary scripts on affected servers. Impacted products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Check Point said it is aware of a handful of customers who have been attacked.

Related Happenings

Check Point Security Management and Log Servers stack overflow security flaw (CVE-2026-91843)

Vulnerability
H score46 First: 17.09.2026 21:08 Last: 17.09.2026 21:08 Sources 1

About this happening: Check Point Security Management Server and Log Server deployments are affected by CVE-2026-91843, a critical stack-based buffer overflow in the login process that...

Latest development: 18.09.2026 03:00

Check Point confirms that R82.20, standalone deployments, Log Servers, and Multi-Domain servers are vulnerable, and says customers who need fixes for out-of-support versions should open a ticket with Check Point support.

Check Point Security Gateways and Security Management Server VPN certificate flaws (multiple vulnerabilities)

Vulnerability
H score53 First: 10.09.2026 14:45 Last: 10.09.2026 14:45 Sources 1

About this happening: Check Point Security Gateways and Security Management Server are affected by two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that can let an...

Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India

Campaign
H score22 First: 12.08.2026 16:35 Last: 12.08.2026 16:35 Sources 1

About this happening: Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India,...

Latest development: 12.08.2026 18:38

Lazarus broadened the Operation Dream Job campaign against defense, aerospace, and aviation organizations in Europe and India by using fraudulent recruitment offers, with successful targeting also observed in Western Europe, including France and Germany, and activity extending into South America, including Brazil. Check Point also tied the latest wave to the Troy backdoor, a FudModule variant with a CVE-2026-68820 exploit, and compromised Roundcube instances used to hide malicious communications and deploy the RelayShell web shell.

CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)

Exploitation Wave
H score89 First: 04.05.2026 11:25 Last: 04.05.2026 11:25 Sources 1

About this happening: CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...

CISA KEV mitigation for BeyondTrust CVE-2026-1731

Advisory/Mitigation
H score46 First: 20.02.2026 19:02 Last: 20.02.2026 19:02 Sources 1

About this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...

Timeline

  1. 23.09.2026 09:14 2 articles · 0h ago

    Check Point warns of exploited CVE-2026-93616 in Management Server

    Initial Disclosure

    Check Point announced urgent patches for CVE-2026-93616, a critical directory traversal and file upload flaw in Management Server products that can let unauthenticated attackers upload and execute arbitrary scripts. The company said the vulnerability is being exploited in the wild and that it is aware of a handful of customers who have been attacked.

    Show sources
  2. 23.09.2026 09:14 1 articles · 0h ago

    Check Point releases hotfixes and IoCs for CVE-2026-93616

    Mitigation Patch Update

    Check Point released the R82.20 Security Hotfix (TAR) and included fixes for CVE-2026-93616 in the Jumbo Hotfix Accumulator for R82.10 (Take 45), R82 (Take 127), R81.20 (Take 170), and R81.10 (Take 192). The company also released indicators of compromise (IoCs), warned that standard LivePatch updates do not resolve CVE-2026-93616, and advised customers to restrict Management Server access behind a security gateway or firewall and limit TCP/19009 to trusted IP addresses.

    Show sources