critical Cve 2026 93616 · Exploits

Check Point Management Servers Were a Zero-Day for Two Months Before the Fix

Data graphic: a huge red 61 over a halftone field, for the 61 days Check Point management servers were exploited through CVE-2026-93616 before a fix. First attacks 23 Jul; fix and CISA KEV listing of both CVEs 22 Sep; CVSS 9.8.
AK

Threat intelligence editor · Updated Oct 2, 2026, 8:05 AM EDT

Attackers exploited Check Point CVE-2026-93616 for root on management servers from 23 July; the fix came 22 September, alongside gateway VPN bug CVE-2026-85102.

Attackers were inside Check Point management servers for two months before anyone outside knew the hole existed. Check Point says it first saw exploitation of CVE-2026-93616, a pre-authentication flaw in the management server's web services, on 23 July 2026. The fix and the public advisory came on 22 September. On the same day CISA added it to the Known Exploited Vulnerabilities catalog alongside a second Check Point bug, CVE-2026-85102, a VPN certificate-validation flaw in Quantum Security Gateways that attackers began using three days after its patch shipped. Both score 9.8.

The management flaw is the one to worry about most. A Security Management Server holds the policy, the objects and the trust relationships for every gateway it manages. Code execution as root there is not one compromised box; it is the control plane for the whole firewall estate. On 1 October Bishop Fox published a full technical write-up of the bug, rebuilt from the patch, so the number of people who know how to exploit it is now much larger than "a handful".


What happened

CVE-2026-93616 is a directory traversal and file upload flaw (CWE-22). NVD's description is short: it "allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server." Check Point's own advisory, sk1000171, lists the affected products as Security Management Server, Multi-Domain Security Management Server, Log Server and SmartEvent. In its security blog the company describes "a handful of pinpointed exploitation" and says attacks were observed from 23 July.

CVE-2026-85102 is improper certificate trust validation (CWE-295) during VPN negotiation on Quantum Security Gateways and Spark firewalls. An unauthenticated remote attacker can execute code on the gateway. Check Point patched it on 9 September and saw exploitation from 12 September, aimed at Spark customers worldwide and coming from VPN and proxy infrastructure. After getting in, the attackers ran internal port and service scans.

CISA listed both on 22 September with a federal remediation deadline of 25 September, three days later. Its KEV entries also point agencies at its forensics triage requirements, which means looking for compromise, not only patching.

How the management exploit works

Bishop Fox's write-up, "One Port to Root", traced the bug by diffing vulnerable and patched builds. The patch replaced three jars: upgrade_web_services.jar, dleserver.jar and java_is.jar. The researchers validated the chain end to end against unpatched R81.10 and R82.10 lab servers.

The target is the CPM Java process, which exposes SOAP web services through Apache CXF under /cpmws/ on TCP/19009. The chain has four steps:

Data graphic: the CVE-2026-93616 exploit chain. A SOAP call to TCP/19009 spoofs a READ_WRITE session via loginNew, a ../ upload writes a file as root, overwriting /etc/cron.d/raid-check runs the payload as root, and downloadRawFile reads the output back.

The four-step chain Bishop Fox rebuilt from the patch, from an unauthenticated call on TCP/19009 to root. Source: Bishop Fox.

  1. Spoof a session. A call to loginNew on LoginSvcRemote mints a READ_WRITE session by impersonating the server's own SIC identity. The remote-authentication path does not verify the certificate.
  2. Write anywhere as root. FileSvcRemote.uploadFileToServerFileSystem does not validate the destination filename, so a ../ sequence writes an attacker's file to any path on the box.
  3. Trigger execution. Overwriting /etc/cron.d/raid-check runs the payload at the next minute boundary, as root.
  4. Read the output. FileSvcRemote.downloadRawFile returns the results over MTOM.

Check Point's blog adds that the flaw also enables arbitrary Java class loading, which gives an attacker a second route to code execution inside the CPM process.

Who is affected

CVE-2026-93616 (management). Per sk1000171:

VersionVulnerableFixed in
R82.20No Jumbo HotfixR82.20 security hotfix
R82.10Jumbo Hotfix Take 44 or lowerTake 45
R82Jumbo Hotfix Take 126 or lowerTake 127
R81.20Jumbo Hotfix Take 166 or lowerTake 170
R81.10 (end of support)Jumbo Hotfix Take 190 or lowerTake 192
R81, R80.x (end of support)AllNo fix; upgrade

There is no LivePatch for this one; it needs the hotfix.

CVE-2026-85102 (gateway VPN). Per sk1000117, only gateways that use certificate authentication are exposed: Site-to-Site VPN with certificates (including DAIP and LSV gateways) and Remote Access through certificate-based Mobile Access. Pre-shared-key VPNs are not affected, and neither is R82.20. Fixed in Jumbo Hotfix R82.10 Take 44, R82 Take 126, R81.20 Take 166 and R81.10 Take 190, Spark R82.00.10 Build 2325 and R81.10.17 Build 4968, or LivePatch Take 26.

Note the overlap. The takes that fix the gateway bug are exactly the takes that are still vulnerable to the management bug. A team that rolled out Jumbo Hotfix R82.10 Take 44 everywhere after the 9 September gateway advisory still has an exploitable management server. Management needs the later take.

What defenders should do

  • Patch management first. Install the fixed Jumbo Hotfix take, or the R82.20 security hotfix, on every Security Management Server, Multi-Domain Server, Log Server and SmartEvent server. Anything still on R81 or R80.x has no fix and should be upgraded.
  • Close TCP/19009. Until the patch is in, allow the port only from trusted administrator addresses, and set Trusted Clients in SmartConsole under Manage & Settings > Permissions & Administrators > Trusted Clients. It should never be reachable from the internet in the first place.
  • Check whether you are exposed. Bishop Fox released a safe external check. It sends a targetVersion parameter with an illegal ! character: a patched server rejects it with "targetVersion contains illegal characters", while a vulnerable one processes it and fails harmlessly.
  • Hunt on management servers. Check Point says to look in cpm.elg for authentication attempts with unusually long usernames, for ../ sequences in file paths, and for FWM or MDS core dumps. Bishop Fox recommends file-integrity checks on /etc/cron.d, authorized_keys, /opt/CPupgrade-tools-*/jars/, configuration files and $FWDIR/conf/SMC_Files. Any hit means treating the policy, admin credentials and SIC trust as compromised.
  • Patch certificate-based VPN gateways. If you cannot patch at once, Check Point's interim mitigation is to disable the VPN implied rules and write explicit rules: UDP/500 and UDP/4500 from known Site-to-Site peers, and UDP/500, UDP/4500, TCP/443 and TCP/80 from expected Remote Access client ranges.
  • Hunt on gateways. Search Mobile Access logs from 12 September onward for certificate logins with the subjects CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global or CN=vpnuser,OU=users,O=global, and look for follow-up activity from those users.

TF covered an earlier Check Point management-plane flaw in July, the SmartConsole authentication bypass CVE-2026-16232. The lesson from both is the same: the management server is the most valuable machine in a Check Point deployment, and its ports belong on an admin-only network.

Sources

Keep reading

All latest →
  1. highExploitsWordPress Core Flaw CVE-2026-87902 Drew Exploit Attempts on Patch Day7 min
  2. criticalExploitsCisco SD-WAN Manager Zero-Day CVE-2026-76504: One Encoded Character Unlocks the Admin API5 min
  3. criticalExploitsExploited FortiMail Flaw Has No Patch Yet: Disable IBE Now5 min
  4. criticalExploitsCitrix NetScaler Zero-Days Planted Webshells Weeks Before the Patch8 min
  5. criticalExploitsUnder Active Attack: Cisco ISE Zero-Day (CVE-2026-76460) Grants Remote Unauthenticated Admin Access8 min
  6. criticalExploitsShieldCrash Zero-Day Analysis: Bypassing Microsoft Defender's ShieldBreak Fix (CVE-2026-69414) for Arbitrary SYSTEM File Reads7 min