A critical zero-day in Check Point's Security Management Server , with the identifier CVE-2026-93616 and CVSS score of 9.8, has been exploited in targeted attacks. The vulnerability allows an unauthenticated attacker to execute script from an arbitrary path via the management service.

Check Point's official update states that the company detected a limited number of targeted attacks on July 23, 2026 , and fixes are now available. The company has not disclosed the targets or the identity of the perpetrators.
See also: Critical vulnerability in Check Point management allows code execution
Check Point Management Server: How CVE-2026-93616 Works
CVE -2026-93616 is a path traversal in the Check Point Management Server web service. The vulnerability allows an attacker who can reach the service to bypass the intended paths restriction and execute script from an arbitrary location.
Simply put, the attacker does not need to log in to an account, while the attack can lead to code execution in the system that manages the gateways' security policies. The severity is reflected in the CVSS score of 9.8, but the actual level of exposure depends on whether the management service is accessible from an untrusted network.
The Hacker News notes that Check Point did not specify what the attackers did after the exploit or whether the attacks continued. The available update should therefore be read as a warning for immediate remediation and control, not a full description of the campaign.

Affected versions and fixes
Check Point lists Security Management and specific branch releases R82.20, R82.10, R82, R81.20 and R81.10, along with older versions that are no longer supported. Specifically, –
R82.20 without Jumbo Hotfix installed
R82.10 with Jumbo Hotfix Take 44 or earlier
R82 with Jumbo Hotfix Take 126 or earlier
R81.20 with Jumbo Hotfix Take 166 or earlier
R81.10 with Jumbo Hotfix Take 190 or earlier (end of support)
R81, R80.40, R80.30, R80.20, R80.10 and R80 (all end of support)
Check Point's security update lists version R82.20 as affected, without the "no Jumbo Hotfix" requirement.
BleepingComputer reports that the fix is available with the Security Hotfix for R82.20. Check Point's instructions include the exact versions, fixed Takes, validation commands, and violation indicators. Administrators should consult support article sk1000171 before selecting an update package.
Special care is needed because LivePatch Take 28 or 29, which fixed a different Management Server vulnerability, does not fix CVE-2026-93616. Installing a recent update is not proof that the specific vulnerability has been patched; checking the exact branch and Take number is required.
See also: Check Point, Kaspersky and Tanium patch critical vulnerabilities
Access restriction and violation control
Until the update is complete, management systems should be placed behind a firewall and access restricted to known administrator addresses. The Trusted Clients in SmartConsole needs to be re-checked to disallow access from any address or directly from the internet.
Check Point asks customers to use the sk1000171 breach indicators and review logs for requests that do not match the normal operation of the service. The absence of obvious symptoms does not rule out a successful attack, especially when an attacker can execute code before the normal login process.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In the event of suspicious activity, security teams should maintain off-site copies of logs, isolate the system according to the incident response plan, and check for changes to accounts, policies, and files . Patch installation should be combined with investigation , because the update alone does not explain what happened before it.
The SecNews technical team also recommends recording the software branch, active Take, and installation time for each Check Point Management Server. This audit helps identify systems that have been missed, especially in environments with multiple Log Servers, Multi-Domain installations, or older, unsupported versions.
See also: Check Point VPN Vulnerabilities: Warning for Immediate Exploitation
Immediate priority for CVE-2026-93616
CVE-2026-93616 combines pre-authentication access, high score, and confirmed exploitation in targeted attacks. Organizations using Check Point Management Server should immediately check the version, apply the appropriate hotfix, and restrict access until remediation is complete.

The SecNews editorial team reminds that the manufacturer's instructions take precedence over any general recommendation, because the fixed Builds vary by branch and configuration. After the update, it is necessary to re-check Trusted Clients and monitor for any suspicious activity.
