A Critical Security Management Server Vulnerability Has Been Exploited in the Wild, Warns Check Point
Check Point Software has issued emergency hotfixes to address a critical vulnerability in its Security Management Server that could allow attackers to run arbitrary scripts. This path traversal flaw, tracked as CVE-2026-93616, allows unauthenticated threat actors to upload and execute malicious scripts on vulnerable systems with ease.
The Security Management Server is a central repository that stores and manages security policies, processes administrator changes, and collects system logs across enterprise networks. Its vulnerability has significant implications for organizations that rely on Check Point’s products for their cybersecurity posture. The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have urged software companies to remove path traversal weaknesses from their products since 2024, calling such security issues “unforgivable.”
Check Point has confirmed that this vulnerability is being exploited in real-world attacks, with a handful of customers having been targeted. The company advises security teams to check their networks for evidence of successful exploitation using the indicators of compromise shared in its security advisory. In addition, Check Point provides temporary mitigation measures for customers who cannot immediately deploy the hotfix on vulnerable systems. These include hardening vulnerable systems against attacks by placing them behind a firewall and limiting access to trusted IP addresses.
The recent exploit of this vulnerability is not an isolated incident. In recent months, Check Point has warned customers that other flaws were being actively exploited in the wild. For instance, CISA flagged a flaw (CVE-2024-24919) in Check Point’s Quantum Security Gateways as actively exploited by ransomware gangs two years ago. This trend highlights the importance of timely patching and vulnerability management for organizations that rely on Check Point’s products.
In light of this latest development, it is essential for security teams to prioritize patching and updating their systems with the latest hotfixes. Regularly reviewing system logs and monitoring network activity can also help identify potential attacks. Furthermore, following best practices for hardening systems against attacks by limiting access and placing them behind firewalls can significantly reduce the risk of exploitation.
Ultimately, this incident serves as a reminder that even well-established security products can have vulnerabilities that are exploited in real-world attacks. Organizations must remain vigilant and proactive in their cybersecurity posture to stay ahead of emerging threats. By staying informed about vulnerabilities and taking prompt action to address them, organizations can minimize the risk of successful attacks and protect their sensitive data and systems.
Source: Bleeping Computer — 2026-09-22