๐Ÿ”ด CVE-2026-93616

CVE-2026-93616 is a critical (CVSS 9.8) directory traversal and arbitrary file upload vulnerability in Check Point Quantum Security Management Server that allows an unauthenticated remote attacker to upload and execute arbitrary scripts โ€” including malicious Java classes โ€” on the management server with no authentication or user interaction required. Active exploitation in the wild has been confirmed by Check Point. Successful exploitation grants full control over the management server, which in turn provides visibility into and control over the entire security infrastructure it manages.

โ† Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 โ€” Exploit Public-Facing Application
ATT&CK Technique
MEDIUM
Deployment Risk
No
Ransomware

๐Ÿ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-09-22

Added to CISA KEV: 2026-09-22 0 DAY BETWEEN CVE AND KEV

๐ŸŽฏ Recommendations:

๐Ÿ” Web Intelligence (Kagi ยท 2026-09-22)

Summary

CVE-2026-93616 is a critical directory traversal and file upload vulnerability affecting Check Point Quantum Security Management servers. It allows an unauthenticated, remote attacker to bypass authentication mechanisms to upload and execute arbitrary scripts, as well as load arbitrary Java classes on the target system. Because it grants full control over the management server, this vulnerability poses a severe risk to the security of the entire network managed by the compromised instance.

Exploitation

  • Active Exploitation: The vulnerability is currently being exploited in the wild, with Check Point reporting a "handful" of customers targeted in pinpointed attacks.
  • Threat Actors: Specific threat actors or named ransomware campaigns have not been publicly identified in initial reports as of September 22, 2026.
  • Proof-of-Concept: There are no widespread public proof-of-concept exploits; however, given the active exploitation, such tools are likely in the hands of sophisticated attackers.
  • Attack Prerequisites:
* Network: The vulnerability is exploitable over the network (remote). * Authentication: No authentication is required (pre-authentication). * User Interaction: No user interaction is required for a successful attack.

Affected Products & Patches

  • Affected Products: Check Point Quantum Security Management servers are impacted.
  • Patches: Check Point has released a fix for this vulnerability. Administrators are advised to refer to the official security advisory and apply the necessary updates immediately to their management environments.
  • Mitigations: Beyond applying the official patches provided by Check Point, there are no documented alternative workarounds to safely mitigate the risk of this vulnerability.

Impact

  • Access/Capabilities: Successful exploitation grants an attacker the ability to execute arbitrary scripts and load malicious Java classes, effectively resulting in full control over the Check Point Management Server.
  • Business Risk: For internet-facing deployments, this vulnerability is critical (CVSS score of 9.8). It enables attackers to compromise the central management hub of the security infrastructure, which can lead to complete network visibility, data exfiltration, lateral movement, and the potential disruption or reconfiguration of security policies across the entire organization.