bleeping-computer · Crawled Sep 22, 2026

Check Point warns of Management Server zero-day exploited in attacks

Read original article ↗

AI Summary

Check Point has released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-93616, in its Security Management Server that allows unauthenticated attackers to perform path traversal and upload and execute arbitrary scripts. The vulnerability is actively exploited in the wild, with Check Point confirming attacks against a handful of customers. The affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. CISA and FBI have previously warned software vendors about the persistence of such path traversal flaws, which remain a high-risk attack vector.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.