Attackers exploited Check Point CVE-2026-93616 for root on management servers from 23 July; the fix came 22 September, alongside gateway VPN bug CVE-2026-85102.
Attackers were inside Check Point management servers for two months before anyone outside knew the hole existed. Check Point says it first saw exploitation of CVE-2026-93616, a pre-authentication flaw in the management server's web services, on 23 July 2026. The fix and the public advisory came on 22 September. On the same day CISA added it to the Known Exploited Vulnerabilities catalog alongside a second Check Point bug, CVE-2026-85102, a VPN certificate-validation flaw in Quantum Security Gateways that attackers began using three days after its patch shipped. Both score 9.8.
The management flaw is the one to worry about most. A Security Management Server holds the policy, the objects and the trust relationships for every gateway it manages. Code execution as root there is not one compromised box; it is the control plane for the whole firewall estate. On 1 October Bishop Fox published a full technical write-up of the bug, rebuilt from the patch, so the number of people who know how to exploit it is now much larger than "a handful".
What happened
CVE-2026-93616 is a directory traversal and file upload flaw (CWE-22). NVD's description is short: it "allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server." Check Point's own advisory, sk1000171, lists the affected products as Security Management Server, Multi-Domain Security Management Server, Log Server and SmartEvent. In its security blog the company describes "a handful of pinpointed exploitation" and says attacks were observed from 23 July.
CVE-2026-85102 is improper certificate trust validation (CWE-295) during VPN negotiation on Quantum Security Gateways and Spark firewalls. An unauthenticated remote attacker can execute code on the gateway. Check Point patched it on 9 September and saw exploitation from 12 September, aimed at Spark customers worldwide and coming from VPN and proxy infrastructure. After getting in, the attackers ran internal port and service scans.
CISA listed both on 22 September with a federal remediation deadline of 25 September, three days later. Its KEV entries also point agencies at its forensics triage requirements, which means looking for compromise, not only patching.
How the management exploit works
Bishop Fox's write-up, "One Port to Root", traced the bug by diffing vulnerable and patched builds. The patch replaced three jars: upgrade_web_services.jar, dleserver.jar and java_is.jar. The researchers validated the chain end to end against unpatched R81.10 and R82.10 lab servers.
The target is the CPM Java process, which exposes SOAP web services through Apache CXF under /cpmws/ on TCP/19009. The chain has four steps:
The four-step chain Bishop Fox rebuilt from the patch, from an unauthenticated call on TCP/19009 to root. Source: Bishop Fox.
- Spoof a session. A call to
loginNewonLoginSvcRemotemints a READ_WRITE session by impersonating the server's own SIC identity. The remote-authentication path does not verify the certificate. - Write anywhere as root.
FileSvcRemote.uploadFileToServerFileSystemdoes not validate the destination filename, so a../sequence writes an attacker's file to any path on the box. - Trigger execution. Overwriting
/etc/cron.d/raid-checkruns the payload at the next minute boundary, as root. - Read the output.
FileSvcRemote.downloadRawFilereturns the results over MTOM.
Check Point's blog adds that the flaw also enables arbitrary Java class loading, which gives an attacker a second route to code execution inside the CPM process.
Who is affected
CVE-2026-93616 (management). Per sk1000171:
| Version | Vulnerable | Fixed in |
|---|---|---|
| R82.20 | No Jumbo Hotfix | R82.20 security hotfix |
| R82.10 | Jumbo Hotfix Take 44 or lower | Take 45 |
| R82 | Jumbo Hotfix Take 126 or lower | Take 127 |
| R81.20 | Jumbo Hotfix Take 166 or lower | Take 170 |
| R81.10 (end of support) | Jumbo Hotfix Take 190 or lower | Take 192 |
| R81, R80.x (end of support) | All | No fix; upgrade |
There is no LivePatch for this one; it needs the hotfix.
CVE-2026-85102 (gateway VPN). Per sk1000117, only gateways that use certificate authentication are exposed: Site-to-Site VPN with certificates (including DAIP and LSV gateways) and Remote Access through certificate-based Mobile Access. Pre-shared-key VPNs are not affected, and neither is R82.20. Fixed in Jumbo Hotfix R82.10 Take 44, R82 Take 126, R81.20 Take 166 and R81.10 Take 190, Spark R82.00.10 Build 2325 and R81.10.17 Build 4968, or LivePatch Take 26.
Note the overlap. The takes that fix the gateway bug are exactly the takes that are still vulnerable to the management bug. A team that rolled out Jumbo Hotfix R82.10 Take 44 everywhere after the 9 September gateway advisory still has an exploitable management server. Management needs the later take.
What defenders should do
- Patch management first. Install the fixed Jumbo Hotfix take, or the R82.20 security hotfix, on every Security Management Server, Multi-Domain Server, Log Server and SmartEvent server. Anything still on R81 or R80.x has no fix and should be upgraded.
- Close TCP/19009. Until the patch is in, allow the port only from trusted administrator addresses, and set Trusted Clients in SmartConsole under Manage & Settings > Permissions & Administrators > Trusted Clients. It should never be reachable from the internet in the first place.
- Check whether you are exposed. Bishop Fox released a safe external check. It sends a
targetVersionparameter with an illegal!character: a patched server rejects it with "targetVersion contains illegal characters", while a vulnerable one processes it and fails harmlessly. - Hunt on management servers. Check Point says to look in
cpm.elgfor authentication attempts with unusually long usernames, for../sequences in file paths, and for FWM or MDS core dumps. Bishop Fox recommends file-integrity checks on/etc/cron.d,authorized_keys,/opt/CPupgrade-tools-*/jars/, configuration files and$FWDIR/conf/SMC_Files. Any hit means treating the policy, admin credentials and SIC trust as compromised. - Patch certificate-based VPN gateways. If you cannot patch at once, Check Point's interim mitigation is to disable the VPN implied rules and write explicit rules: UDP/500 and UDP/4500 from known Site-to-Site peers, and UDP/500, UDP/4500, TCP/443 and TCP/80 from expected Remote Access client ranges.
- Hunt on gateways. Search Mobile Access logs from 12 September onward for certificate logins with the subjects
CN=vpn,OU=users,O=global,CN=vpn-user,OU=users,O=globalorCN=vpnuser,OU=users,O=global, and look for follow-up activity from those users.
TF covered an earlier Check Point management-plane flaw in July, the SmartConsole authentication bypass CVE-2026-16232. The lesson from both is the same: the management server is the most valuable machine in a Check Point deployment, and its ports belong on an admin-only network.