CVE-2026-93616: Directory Traversal and File upload allows execution of arbitrary script on the Management Server

Published Sep 22, 2026
·
Updated

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

Other sources

Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.

CISA

Affected Software

2 affected components
Check Point Management Server
Check Point Multiple Products

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Discontinue use of Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent if mitigations are unavailable.

Event History

Sep 22, 2026
CVE Published
via CISA·12:00 AM
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
CVE Published
via MITRE·12:59 PM
Data Sourced
via MITRE·12:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated attacker can exploit it remotely; no credentials or user interaction are required.

2

What is the likely impact of successful exploitation?

Successful exploitation allows upload and execution of arbitrary scripts on the Check Point Management Server, with high impact to confidentiality, integrity, and availability.

3

What should teams prioritize when triaging this vulnerability?

Prioritize internet-reachable or otherwise untrusted-network-accessible Check Point Management Server instances, because the attack vector is network-based and exploitation has low complexity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203