< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

Part of situation: (2 clusters)

Check Point patches critical, actively exploited security flaw

Check Point has released emergency hotfixes to address a critical, actively exploited security flaw in its Security Management Server. The vulnerability, identified as CVE-2026-93616, is a path traversal flaw that allows unauthenticated attackers to upload and execute malicious scripts on vulnerable servers.

Because the Management Server controls security policies, administrator activity, and system logs, a compromise could significantly impact an entire enterprise network. The company noted that the flaw has been exploited in the wild and that a handful of customers have already been targeted. The vulnerability affects several products, including the Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.

Additionally, reports indicate that a separate vulnerability in VPN gateways (CVE-2026-85102) was also targeted by attackers shortly after a previous patch was released. Check Point is urging customers to apply the R82.20 Security Hotfix immediately or, as a temporary measure, restrict access to vulnerable systems via firewalls using trusted IP addresses.

Entities

Check Point