Overview
- Check Point released emergency hotfixes on Sept. 22 for CVE-2026-93616 and published indicators of compromise and hunting guidance for affected customers.
- The flaw is a path‑traversal/file‑upload vulnerability rated 9.8 that allows unauthenticated attackers to upload and execute scripts on Management Server and Log Server appliances.
- The vendor said the bug has been exploited in the wild and that a handful of customers were attacked, and it warned that installing the fix does not prove a system was not previously compromised.
- Check Point included fixes in an R82.20 TAR and Jumbo Hotfix takes for multiple releases and noted LivePatch channels do not address this specific bug, so some administrators must apply TAR/Take updates instead.
- CISA added CVE-2026-93616 to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch within three days, signaling urgent risk to any organization that exposes management interfaces and prompting calls to isolate servers, restrict TCP/19009 to trusted IPs, hunt logs, and rotate credentials.