Vulnerability threat dossier

CVE-2026-93616

checkpointmulti-domain security management

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

VTP deterministic threat49.9of 100 · CVSS excluded

VTP analyst assessment

Check Point Management Server RCE is actively exploited

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

CVE-2026-93616 affects Check Point Management Server. An unauthenticated attacker can use directory traversal and file upload to upload and execute arbitrary scripts. CERT-FR says the vendor reports active exploitation, and ENISA lists the flaw as known exploited.

Why it matters

  • The vulnerable management server controls security administration, so remote code execution can compromise a high-value control plane.
  • The attack requires no authentication according to the CVE description.

Evidence

3 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The Check Point VPN report mapped to this CVE concerns CVE-2026-85102 and does not add context here.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use affected Check Point Management Server products, apply the vendor's remediation immediately.

AI baseline history (3)
  1. BASELINE ASSESSED
    Check Point Management Server RCE is actively exploitedgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Check Point Management Server script executiongpt-5.6-terra · low
  3. BASELINE ASSESSED
    Check Point Management Server path traversal and script uploadgpt-5.6-terra · low
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.2097th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.20; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

CERT ADVISORYNew CERT advisory
ACTIVE EXPLOITATIONENISA EU KEV entry added
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

5publications detected
5underlying evidence chains

2 primary sources · 0 dependent secondary reports · 3 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
64%claim confidence
UNKNOWNreport:90ca8d49f35b2de1fee6cbc88a1090da13a8f6d6914e7ab95a3bc37c33f948caACTIVE
Evidence
Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-93616ACTIVE
Evidence
04

Event history

Threat timeline

  1. 19:5323 Sept
    ZERO DAY

    Zero Day

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 00:0023 Sept
    CERT ADVISORY

    New CERT advisory

    CERT-FR published evidence linked to CVE-2026-93616.

  3. 00:0022 Sept
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. This is public intelligence, not a VTP sensor observation.

  4. 00:0022 Sept
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]

CVE-2026-85102CVE-2026-93616
Separate evidence group
Original

Vulnérabilité dans Check Point Security Management Server (23 septembre 2026)

Une vulnérabilité a été découverte dans Check Point Security Management Server. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et une atteinte à l'intégrité des données. L'éditeur indique que la vulnérabilité CVE-2026-93616 est activement exploitée. Check...

CVE-2026-93616
Separate evidence group
Original

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point

CVE-2026-85102CVE-2026-85103CVE-2026-91843CVE-2026-93616
Separate evidence group
Original

Check Point warns of Management Server zero-day exploited in attacks

Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. [...]

CVE-2024-24919CVE-2026-16232CVE-2026-50751CVE-2026-85102CVE-2026-85103CVE-2026-93616
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-93616

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-93616
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score49.9vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction3.93 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency6 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-22
CPE records
242
Deterministic history records
11
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.