Check Point warns of Management Server zero-day exploited in attacks
Read original article ↗AI Summary
Check Point has released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-93616, in its Security Management Server that allows unauthenticated attackers to perform path traversal and upload and execute arbitrary scripts. The vulnerability is actively exploited in the wild, with Check Point confirming attacks against a handful of customers. The affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. CISA and FBI have previously warned software vendors about the persistence of such path traversal flaws, which remain a high-risk attack vector.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.