A Critical Vulnerability Exposed in Check Point Management Servers, Leaving Enterprises at Risk
A recently discovered zero-day vulnerability in Check Point’s Security Management Server has been exploited in the wild, putting thousands of organizations at risk. The critical path traversal flaw allows unauthenticated attackers to upload arbitrary scripts and execute them with ease, making it a highly sought-after exploit for threat actors.
The Security Management Server is a central hub that manages security policies, monitors system logs, and processes administrator changes across an enterprise network. With this vulnerability, attackers can gain unauthorized access to sensitive data and disrupt critical operations. Check Point has released emergency hotfixes to address the issue, but it’s unclear how many organizations have already been compromised.
The vulnerability, tracked as CVE-2026-93616, was flagged by Check Point as being actively exploited in attacks. The company warned that a handful of customers have been targeted, and security teams should be on high alert for signs of successful exploitation. To mitigate the risk, Check Point recommends hardening vulnerable systems against attacks by placing them behind a firewall and limiting access to trusted IP addresses.
The discovery is particularly concerning given the Cybersecurity and Infrastructure Security Agency (CISA) and FBI’s warning in May 2024 that software companies should remove path traversal weaknesses from their products. The agencies have repeatedly emphasized the importance of addressing such security issues, which they deem “unforgivable” since at least 2007.
This is not an isolated incident for Check Point. In recent months, the company has warned customers about several other actively exploited vulnerabilities in its products. For instance, CISA flagged a flaw (CVE-2024-24919) in Quantum Security Gateways two years ago, confirming reports that ransomware gangs were exploiting it. Similarly, Qilin ransomware affiliates have exploited authentication bypass zero-days since June and July.
The Dutch National Cyber Security Centre (NCSC-NL) also warned organizations to patch critical Check Point VPN flaws last week, citing expected exploitation attempts soon. Given the frequency of these incidents, enterprises should take immediate action to secure their networks.
To protect themselves from this vulnerability, security teams should prioritize deploying the emergency hotfixes as soon as possible. In the meantime, they can implement temporary mitigation measures, such as hardening vulnerable systems against attacks. It’s essential for organizations to stay vigilant and regularly monitor their networks for signs of successful exploitation. By taking proactive steps to address this critical vulnerability, enterprises can minimize the risk of a devastating attack on their operations.
Source: Bleeping Computer — 2026-09-22