Check Point Patches Critical CVE-2026-93616 Flaw Actively Exploited in the Wild
Check Point disclosed a critical pre-authentication vulnerability, CVE-2026-93616, affecting its Security Management Server and related products, with a CVSS v3.1 score of 9.8. The flaw allows an unauthenticated remote attacker to exploit directory traversal and file upload weaknesses on TCP port 19009 to execute arbitrary scripts or load malicious Java classes without any user interaction. Check Point confirmed observing a small number of targeted attacks in the wild as of July 23, 2026, though specific payloads and post-compromise actions have not been publicly disclosed. Affected versions span multiple release branches including R82.20, R81.20, R81.10, and several end-of-support versions such as R80 through R81. Check Point has released security hotfixes, and administrators are advised to apply the relevant patches immediately to mitigate active exploitation risk.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in