Check Point Warns of Actively Exploited Zero-Day in Security Management Server
Check Point has confirmed that a previously unknown vulnerability in its Security Management Server, the system that controls firewall policies for its gateway products, was exploited in a small number of targeted attacks on 23 July. The flaw, tracked as CVE-2026-93616, is a path traversal bug in the server's web service that lets an attacker upload and run scripts without logging in. It has been rated 9.8 out of 10 on the CVSS severity scale. A fix was released on 22 September, meaning the vulnerability was actively exploited for around two months before a patch existed.
Check Point has not named the organisations targeted in the July attacks or identified the attackers, and has not disclosed what actions were taken after the flaw was exploited. Separately, the company reported that since 12 September, attackers have been attempting to exploit a different flaw, CVE-2026-85102, in its Spark line of firewalls designed for small businesses. That vulnerability was patched on 9 September, and Check Point says it had no evidence of exploitation at the time of that release.
Check Point has published detailed guidance, including fixed software versions, mitigation steps, and indicators of compromise, in its support article sk1000171. Administrators are urged to review this guidance closely, as some earlier patches for related flaws do not address CVE-2026-93616.