CVE-2026-93616 is a critical (CVSS 9.8) directory traversal and arbitrary file upload vulnerability in Check Point Quantum Security Management Server that allows an unauthenticated remote attacker to upload and execute arbitrary scripts โ including malicious Java classes โ on the management server with no authentication or user interaction required. Active exploitation in the wild has been confirmed by Check Point. Successful exploitation grants full control over the management server, which in turn provides visibility into and control over the entire security infrastructure it manages.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-22
Added to CISA KEV: 2026-09-22 0 DAY BETWEEN CVE AND KEV
CVE-2026-93616 is a critical directory traversal and file upload vulnerability affecting Check Point Quantum Security Management servers. It allows an unauthenticated, remote attacker to bypass authentication mechanisms to upload and execute arbitrary scripts, as well as load arbitrary Java classes on the target system. Because it grants full control over the management server, this vulnerability poses a severe risk to the security of the entire network managed by the compromised instance.