Catalog analysis: CISA added this entry on September 22, 2026. The entry reflects catalog information retrieved on September 23, 2026, not a snapshot archived on the inclusion date. This site’s publication date is shown separately. Check current vendor guidance before acting.
What the vulnerability is
CVE-2026-93616 is a path traversal vulnerability (CWE-22) affecting multiple Check Point products. The flaw allows an unauthenticated attacker to upload and execute arbitrary scripts on the affected system. Due to the potential for remote code execution without authentication, CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on September 22, 2026.
Exposure and applicability
This vulnerability applies to organizations utilizing the following Check Point components:
* Security Management Server
* Multi-Domain Security Management Server
* Log Server
* Multi-Domain Log Server
* SmartEvent
Exposure is highest for assets with direct internet visibility. Organizations must evaluate the network placement of these management and logging servers to determine the immediate risk of unauthenticated external access.
Remediation priorities
Based on our analysis, vulnerability management teams should prioritize actions in the following order:
- Immediate Mitigation Application: Apply the mitigations specified in vendor advisory sk1000171. This is the primary corrective action to close the path traversal entry point.
- Forensic Triage: Because CISA has flagged this vulnerability for forensic triage, defenders should examine these assets for indicators of unauthorized script uploads or execution prior to and following the mitigation process.
- Exposure Reduction: Review firewall rules and access control lists (ACLs) to ensure management interfaces are not exposed to untrusted networks, reducing the likelihood of unauthenticated exploitation.
How to validate remediation
Verification must go beyond a simple version check or the presence of a patch. To assure that exposure has been reduced, defenders should:
* Confirm Mitigation State: Verify through vendor-provided tools or configuration checks that the specific mitigations outlined in sk1000171 are active and functioning.
* Audit File Integrity: Check for the existence of unexpected scripts in directories typically targeted by path traversal attacks on these platforms.
* Validate Access Controls: Confirm that only authorized administrative IPs can reach the management services, ensuring that any residual vulnerability is not reachable by unauthenticated external actors.
Limits and open questions
While vendor mitigations address the known flaw, there is a risk of residual exposure if forensic triage reveals that an attacker had already established persistence before the fix was applied. It remains unknown whether this vulnerability has been utilized in specific ransomware campaigns. Furthermore, while federal agencies face a CISA-mandated deadline of September 25, 2026, non-federal organizations must determine their own urgency based on their specific threat profile and asset exposure.
Source and editorial note
CVE-2026-93616: Check Point Multiple Products Path Traversal Vulnerability · Source date: September 22, 2026 · Retrieved September 23, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗