Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)

Check Point Patches Actively Exploited Zero-Day Path (TL-2026-2617) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-22. It has no confirmed attribution, affects Check Point Software Technologies Security Management Server, references 1 CVE (CVE-2026-93616), maps to 7 MITRE ATT&CK techniques (T1059, T1190, T1505), and is covered by 9 detection rules and 8 indicators of compromise.

Key facts for TL-2026-2617

Threat ID
TL-2026-2617
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-22
Last reviewed
2026-09-22
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
8

Check Point disclosed and same-day patched CVE-2026-93616, a pre-authentication path traversal (CWE-22) and unrestricted file upload (CWE-434) flaw, CVSS 9.8, in the Management web service of Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent that lets an unauthenticated attacker execute a script from an arbitrary path and load an arbitrary Java class. Check Point confirmed pinpointed in-the-wild exploitation against a handful of customers beginning 2026-07-23 and shipped an R82.20 Security Hotfix plus Jumbo Hotfix updates for supported branches.

How Check Point Patches Actively Exploited Zero-Day Path works

CVE-2026-93616 is a pre-authentication directory traversal and unrestricted file upload vulnerability in the web service that fronts Check Point's central management stack (Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent). An unauthenticated network attacker can supply a crafted path to upload an arbitrary script and, per Check Point's own advisory, cause the server to 'execute a script from an arbitrary path and load an arbitrary Java class' — turning a filesystem-scoping bug into unauthenticated remote code execution on the appliance that holds policy, logs, and administrative control for an organization's entire Check Point estate. Independent analysis (Strix) characterizes the root cause as directory traversal combined with unrestricted file-upload capability, i.e. CWE-22 paired with CWE-434, bypassing the intended access controls on where an uploaded file may land and what it may do once placed. The 'arbitrary Java class' load and the ReflectionUtils artifact in the vendor's own detection guidance indicate the Management Portal (cpm) backend is a Java-based service, consistent with a traversal-then-classload exploitation primitive rather than a native-binary one. Check Point rates the flaw CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and confirmed it 'is exploited in the wild,' with pinpointed attacks against a handful of customers first observed 2026-07-23 — a full two months before the 2026-09-22 public disclosure and R82.20 Security Hotfix release, meeting the definition of a true zero-day. NVD's automated SSVC scoring separately assessed the exploit as 'automatable' with 'total' technical impact, though NVD's exploitation-status field lagged and had not yet reflected Check Point's own confirmed in-the-wild attacks at the time of this record; the vendor's direct statement is treated as authoritative for exploitation status. As of 2026-09-22 the CVE is not yet listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Check Point published CVE-2026-93616 jointly with two companion vulnerabilities disclosed in the same advisory: CVE-2026-85102, an improper-certificate-validation flaw during VPN negotiation on Security Gateway and Spark Firewall (Site-to-Site/Remote Access VPN) that Check Point patched 2026-09-09 and began observing under active exploitation against Spark customers globally from 2026-09-12 using certificates bearing subjects such as CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global, and CN=vpnuser,OU=users,O=global, with attack traffic originating from anonymization infrastructure (VPN services and proxies) and followed by internal port/service scans from suspicious Mobile Access sessions; and CVE-2026-85103, a heap overflow in VPN certificate ASN.1 decoding patched the same day with no confirmed active exploitation. All three carry CVSS 9.8. CVE-2026-93616 is the narrower, longer-running zero-day of the set — a central-management-plane compromise rather than a gateway/VPN compromise — and is the sole CVE in scope for this threat record; the CVE-2026-85102/85103 exploitation details above are recorded for context only and are not folded into this record's MITRE mapping or IOC set.

Check Point's remediation advisory (sk1000171) sets minimum Jumbo Hotfix Take thresholds per branch and ships two Expert-mode grep signatures for retrospective hunting: one flags oversized username fields (>1000 characters) inside LoginRequest entries in cpm.elg, the signature of a traversal payload smuggled through an authentication-adjacent field; the other flags 'Failed to load allResourceFiles map from' errors thrown by upgrade.base.ReflectionUtils in upgrade logs, which occur when a crafted '../'-laden path is fed into the resource-loading routine the exploit abuses, and Check Point explicitly calls out '../' directory-traversal sequences in that log output as a red flag. Check Point notes that failed or partial exploitation attempts have produced FWM/MDS process core dumps under /var/log/dump/usermode/, giving defenders a filesystem artifact to correlate against the log signatures. LivePatch Takes 28/29 do NOT remediate this issue — affected organizations without a qualifying Jumbo Hotfix or the R82.20 Security Hotfix must patch manually. Smart-1 Cloud, Check Point Firewall Appliances (gateway hardware), and Check Point Spark Firewall are explicitly listed by the vendor as unaffected by this particular CVE (Spark is affected by the companion CVE-2026-85102 instead). As an interim compensating control, Check Point recommends restricting TCP/19009 (the management web service port) to trusted administrative IP ranges and configuring SmartConsole Trusted Clients (Manage & Settings > Permissions & Administrators) per the Gateway and Management Hardening Administration Guide. No public proof-of-concept exploit, named threat actor, victim sector, or victim region has been disclosed as of 2026-09-22.

MITRE ATT&CK techniques used in TL-2026-2617

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1190 Exploit Public-Facing Application

Persistence

T1505 Server Software Component

Resource Development

T1587 Develop Capabilities; T1588 Obtain Capabilities

Reconnaissance

T1595 Active Scanning

Defense Evasion

T1620 Reflective Code Loading

Affected products and versions in Check Point Patches Actively Exploited Zero-Day Path

  • Check Point Software Technologies — Security Management Server
    Vulnerable versions: R82.20 (no Security Hotfix); R82.10 Jumbo Hotfix Take ≤44; R82 Jumbo Hotfix Take ≤126; R81.20 Jumbo Hotfix Take ≤166; R81.10 Jumbo Hotfix Take ≤190 (End of Support); R80, R80.10, R80.20, R80.30, R80.40, R81 (all End of Support)
    Fixed in: R82.20 with Security Hotfix; R82.10 Jumbo Hotfix Take 45+; R82 Jumbo Hotfix Take 127+; R81.20 Jumbo Hotfix Take 170+; R81.10 Jumbo Hotfix Take 192+ (End of Support, upgrade recommended)
  • Check Point Software Technologies — Multi-Domain Security Management Server
    Vulnerable versions: R82.20 (no Security Hotfix); R82.10 Jumbo Hotfix Take ≤44; R82 Jumbo Hotfix Take ≤126; R81.20 Jumbo Hotfix Take ≤166; R81.10 Jumbo Hotfix Take ≤190 (End of Support); R80 and earlier (End of Support)
    Fixed in: R82.20 with Security Hotfix; R82.10 Jumbo Hotfix Take 45+; R82 Jumbo Hotfix Take 127+; R81.20 Jumbo Hotfix Take 170+; R81.10 Jumbo Hotfix Take 192+ (End of Support, upgrade recommended)
  • Check Point Software Technologies — Log Server
    Vulnerable versions: R82.20 (no Security Hotfix); R82.10 Jumbo Hotfix Take ≤44; R82 Jumbo Hotfix Take ≤126; R81.20 Jumbo Hotfix Take ≤166; R81.10 Jumbo Hotfix Take ≤190 (End of Support); R80 and earlier (End of Support)
    Fixed in: R82.20 with Security Hotfix; R82.10 Jumbo Hotfix Take 45+; R82 Jumbo Hotfix Take 127+; R81.20 Jumbo Hotfix Take 170+; R81.10 Jumbo Hotfix Take 192+ (End of Support, upgrade recommended)
  • Check Point Software Technologies — Multi-Domain Log Server
    Vulnerable versions: R82.20 (no Security Hotfix); R82.10 Jumbo Hotfix Take ≤44; R82 Jumbo Hotfix Take ≤126; R81.20 Jumbo Hotfix Take ≤166; R81.10 Jumbo Hotfix Take ≤190 (End of Support); R80 and earlier (End of Support)
    Fixed in: R82.20 with Security Hotfix; R82.10 Jumbo Hotfix Take 45+; R82 Jumbo Hotfix Take 127+; R81.20 Jumbo Hotfix Take 170+; R81.10 Jumbo Hotfix Take 192+ (End of Support, upgrade recommended)
  • Check Point Software Technologies — SmartEvent
    Vulnerable versions: R82.20 (no Security Hotfix); R82.10 Jumbo Hotfix Take ≤44; R82 Jumbo Hotfix Take ≤126; R81.20 Jumbo Hotfix Take ≤166; R81.10 Jumbo Hotfix Take ≤190 (End of Support); R80 and earlier (End of Support)
    Fixed in: R82.20 with Security Hotfix; R82.10 Jumbo Hotfix Take 45+; R82 Jumbo Hotfix Take 127+; R81.20 Jumbo Hotfix Take 170+; R81.10 Jumbo Hotfix Take 192+ (End of Support, upgrade recommended)

Remediation for Check Point Patches Actively Exploited Zero-Day Path

Patches

  • R82.20: Security Hotfix (released 2026-09-22, download ID 145601)
  • R82.10: Jumbo Hotfix Accumulator Take 45 or higher
  • R82: Jumbo Hotfix Accumulator Take 127 or higher
  • R81.20: Jumbo Hotfix Accumulator Take 170 or higher
  • R81.10 (End of Support): Jumbo Hotfix Accumulator Take 192 or higher

Immediate actions

  • Apply the R82.20 Security Hotfix on all Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent instances.
  • For R82.10, R82, R81.20, and R81.10 branches without LivePatch, install the minimum required Jumbo Hotfix Take per sk1000171 (R82.10 Take 45+, R82 Take 127+, R81.20 Take 170+, R81.10 Take 192+); note LivePatch Takes 28/29 do NOT remediate this issue.
  • Restrict inbound access to TCP/19009 (the management web service) to trusted administrative IP ranges only.
  • Run the sk1000171 Expert-mode grep signatures against cpm.elg (oversized username in LoginRequest; '../' traversal sequences in ReflectionUtils 'Failed to load allResourceFiles map from' errors) on every management/log/SmartEvent server to check for prior exploitation.
  • Check /var/log/dump/usermode/ for unexpected FWM/MDS core dumps, which Check Point associates with exploitation attempts.

Workarounds

  • Restrict TCP/19009 to trusted administrative IPs only.
  • Enforce SmartConsole Trusted Clients to limit which hosts can reach the management web service.
  • Where feasible, place management servers behind an additional network ACL/firewall layer isolating them from general network access, per Check Point's hardening guidance.

Longer-term hardening

  • Configure SmartConsole Trusted Clients (Manage & Settings > Permissions & Administrators) to restrict which hosts may reach management interfaces.
  • Apply the Check Point Gateway and Management Hardening Administration Guide baseline to all management-plane infrastructure.
  • Upgrade any R80.x or earlier End-of-Support management deployments off unsupported branches; no fix is available for EoS versions.
  • Establish a recurring cadence for validating Jumbo Hotfix currency on management infrastructure given the pattern of pre-auth management-plane CVEs in this vendor's product line.

CVEs associated with Check Point Patches Actively Exploited Zero-Day Path

CVE-2026-93616

Weaknesses (CWE) in Check Point Patches Actively Exploited Zero-Day Path

CWE-22, CWE-434

Timeline of Check Point Patches Actively Exploited Zero-Day Path

  • Check Point first observes pinpointed in-the-wild exploitation attempts against CVE-2026-93616, affecting a handful of customers, well before public disclosure.
  • Check Point discloses and patches companion vulnerability CVE-2026-85103 (heap overflow in VPN certificate ASN.1 decoding) in the same release window; no active exploitation confirmed for this CVE.
  • Check Point discloses and patches companion vulnerability CVE-2026-85102 (VPN certificate validation pre-auth RCE) on Security Gateway and Spark Firewall via Jumbo Hotfix Accumulator, plus an urgent LivePatch Take 24 for eligible systems.
  • Check Point observes a wave of active exploitation of CVE-2026-85102 beginning against Spark Firewall customers globally, using anonymization infrastructure including VPN services and proxies, followed by internal port/service scanning from suspicious Mobile Access sessions.
  • BleepingComputer and other outlets report on the Check Point Management Server zero-day disclosure and patch.
  • CVE-2026-93616 is reserved (2026-09-18) and published to NVD/MITRE the same day as vendor disclosure, with the vulnerability not yet added to the CISA KEV catalog as of this date.
  • Check Point publishes support advisory sk1000171 with per-branch patch levels, hardening guidance, and Expert-mode IOC grep signatures for CVE-2026-93616.
  • Check Point releases the R82.20 Security Hotfix (download ID 145601) and updated Jumbo Hotfix Take thresholds for R82.10, R82, R81.20, and R81.10 to remediate CVE-2026-93616.
  • Check Point publishes a joint security advisory disclosing CVE-2026-93616 as a management-server zero-day exploited against a handful of customers, alongside the earlier-patched CVE-2026-85102.

Sources cited for Check Point Patches Actively Exploited Zero-Day Path

More in vulnerability

Detection coverage for TL-2026-2617

As of 2026-09-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2617 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats