4:00PM, 23 September 2026
TLP Rating:
CVE-2026-93616 affecting Check Point Management Server
CVE-2026-93616 is a directory traversal and file upload vulnerability that exists within the Check Point Management Server which could allow an unauthenticated attacker to upload and execute arbitrary scripts on the Check Point Management Server.
This vulnerability is being exploited in the wild. Check Point is aware of a handful of customers who have been attacked.
The NCSC encourages organisations in New Zealand that use the affected products to review the advisory and apply the remediation as soon as possible. We also urge affected organisations to investigate unauthorised access or compromise of the affected products.
What's happening
Systems affected
Versions that are affected: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, SmartEvent.
- R82.20
- R82.10 Jumbo Hotfix Take 44 or lower
- R82 Jumbo Hotfix Take 126 or lower
- R81.20 Jumbo Hotfix Take 166 or lower
- R81.10 Jumbo Hotfix Take 190 or lower (EoS)
- R80, R80.10, R80.20, R80.30,
- R80.40, R81 (all EoS)
Note: Check Point LivePatch Take 28/29 does not address this issue.
What to look for
How to tell if you're at risk
If you are running one of the affected products within the version range listed above.
What to do
Prevention
To prevent exploitation, the affected Check Points products need to be upgraded to the latest versions per the vendor advisory.
Mitigation
Check Point have provided mitigation advice which is available in their advisory.
More information
Read more about this alert on the vendor website:
CVE-2026-93616 - Check Point External Link
If you require more information or further support, submit a report on our website: