Check Point Security Management Server Pre-Authentication Path Traversal Vulnerability
Release Date: 22nd September 2026 (Added 23 September 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-93616 is a critical pre-authentication path traversal vulnerability (CWE-22) in the Check Point management web service, affecting Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. The flaw allows an unauthenticated remote attacker to write to an arbitrary path on the server, leading to script execution and Java class loading, and ultimately remote code execution on the management appliance. CVSS score: 9.8 (Critical).
What are the systems affected?
The following Check Point Security Management versions are affected:
- R82.20
- R82.10 with Jumbo Hotfix Take 44 or lower
- R82 with Jumbo Hotfix Take 126 or lower
- R81.20 with Jumbo Hotfix Take 166 or lower
- R81.10 with Jumbo Hotfix Take 190 or lower (End of Support)
- R80, R80.10, R80.20, R80.30, R80.40, and R81 (all End of Support)
Not affected / patched version:
- Updated Jumbo Hotfix builds addressing CVE-2026-93616 for R82.20, R82.10, R82, and R81.20. Check Point's support article SK1000171 gives the exact hotfix build, validation commands, and alternative mitigation steps for each version; versions already at End of Support (R80.x, R81, and R81.10 past Take 190) should be prioritized for migration to a supported release.
What does this mean?
Successful exploitation may allow attackers to:
- Write files to an arbitrary path on the management server without any authentication
- Execute arbitrary scripts or load malicious Java classes on the management server, leading to remote code execution
- Gain control of the Security Management, Multi-Domain, Log, or SmartEvent server that centrally manages an organization's Check Point security policy and logs — a high-value target given the scope of access such a server typically holds
Mitigation process?
CERTVU recommends the following:
-
Apply the vendor hotfix as an emergency change
Apply the Jumbo Hotfix Take addressing CVE-2026-93616 for your specific version, per Check Point support article SK1000171, without delay given confirmed active exploitation. -
Migrate any End-of-Support version
R80.x, R81, and R81.10 past Take 190 are End of Support and will not receive further security fixes; migrate these to a supported, patched release as soon as possible. -
Restrict access to the management web service
Limit network access to the Check Point management web interface to trusted administrative hosts and networks only, since this flaw requires no authentication to exploit. -
Treat this as top priority
Reference
- https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-93616
- Download advisory (English): Check Point Security Management Server Pre-Authentication Path Traversal Vulnerability