Particle.news

Check Point Ships Emergency Fix for Actively Exploited Management Server Zero‑Day

Installing the update is needed to stop attackers from uploading and running scripts on central management servers.

Overview

  • Check Point confirmed a critical path‑traversal zero‑day, tracked as CVE‑2026‑93616, was used in targeted attacks that the company says occurred on July 23 and lets unauthenticated users upload and execute scripts on the Security Management Server.
  • On September 22 Check Point published emergency hotfixes and support article sk1000171 with indicators of compromise and step‑by‑step hunting guidance so defenders can check for past compromise and install the fixes.
  • The flaw scores 9.8 on the CVSS scale and affects multiple products including Security Management Server, Multi‑Domain Management, Log Server and SmartEvent across many releases and specific Jumbo Hotfix take numbers, so administrators must verify exact build and take values rather than only release names.
  • If teams cannot apply the hotfix right away Check Point recommends temporary network controls such as allowing management access only from trusted IPs, using LivePatch where offered, and checking logs for the IOCs the company published.
  • Separate attempts to exploit a September 9 VPN certificate/validation flaw were observed beginning September 12, and the string of management and gateway flaws since July raises the risk that undetected intrusions could let attackers change policies, erase logs, or spread across networks.