CVE-2026-93616: Directory Traversal and File upload allows execution of arbitrary script on the Management Server
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
Other sources
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent if mitigations are unavailable.
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker can exploit it remotely; no credentials or user interaction are required.
What is the likely impact of successful exploitation?
Successful exploitation allows upload and execution of arbitrary scripts on the Check Point Management Server, with high impact to confidentiality, integrity, and availability.
What should teams prioritize when triaging this vulnerability?
Prioritize internet-reachable or otherwise untrusted-network-accessible Check Point Management Server instances, because the attack vector is network-based and exploitation has low complexity.