Check Point Security Management Server Pre-Authentication Path Traversal Vulnerability

Release Date: 22nd September 2026 (Added 23 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-93616 is a critical pre-authentication path traversal vulnerability (CWE-22) in the Check Point management web service, affecting Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. The flaw allows an unauthenticated remote attacker to write to an arbitrary path on the server, leading to script execution and Java class loading, and ultimately remote code execution on the management appliance. CVSS score: 9.8 (Critical).

Reference

  1. https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-93616