CVE-2026-93616 actively exploited: Check Point Multiple Products Path Traversal Vulnerability
CISA added CVE-2026-93616, a path traversal in Check Point Multiple Products, to its Known Exploited Vulnerabilities catalogue. It allows an unauthenticated attacker to upload and execute arbitrary scripts. Federal agencies must remediate by September 25, 2026.
Check Point identified a path traversal flaw across several management tools. This defect permits a remote user without credentials to place and run unwanted code. The affected components include the Security Management Server and its multinode counterpart. Log servers and the SmartEvent interface also face this exposure. Organizations deploying these specific Check Point products are vulnerable. The issue impacts both standard and multi-domain server setups. Entities using SmartEvent for log analysis remain at risk. CISA confirmed that ransomware groups have not yet used this specific flaw in attacks. Admins should implement vendor-recommended patches immediately. Federal agencies must complete these updates by September 25, 2026. Teams need to verify internet exposure for each asset. If no fix exists, they must follow BOD 26-04 guidance. Cloud service users have additional obligations. Discontinuing the product is required if mitigations fail.