AI DRAFT / HUMAN REVIEW

This briefing was produced by AI from the linked sources and is scheduled for human editorial review within 24 hours. Read the sources directly for material decisions.

EVIDENCE — Check Point updated its advisory on 22 September 2026 for CVE-2026-93616, a CVSS 9.8 directory-traversal and file-upload vulnerability in its management-server software. The company says the flaw is being exploited in the wild and that a handful of customers have been attacked. Successful exploitation requires no authentication and can upload and execute an arbitrary script on the management server.

THE CONTROL PLANE WAS THE TARGET — Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Those systems hold policy, topology, logs, and administrative trust for the protected estate, so script execution there is not an isolated application compromise. Check Point lists Smart-1 Cloud as already fixed and says its firewall appliances and Spark firewalls are not affected; the urgent inventory is the management and logging tier.

THE VERSION LINE HAS SHARP EDGES — Check Point identifies R82.20, R82.10 Jumbo Hotfix Take 44 or lower, R82 Take 126 or lower, R81.20 Take 166 or lower, R81.10 Take 190 or lower, and all R80 through R81 end-of-support branches as affected. The advisory specifically warns that LivePatch Take 28 or 29 does not address CVE-2026-93616. A dashboard showing a recent LivePatch therefore does not establish that the management server is safe.

THE FIX REQUIRES THE RIGHT HOTFIX — Check Point provides a dedicated R82.20 Security Hotfix and includes the correction in R82.10 Jumbo Hotfix Take 45 or later, R82 Take 127 or later, R81.20 Take 170 or later, and R81.10 Take 192 or later. The vendor says no LivePatch will be available because of the nature of the fix. Until remediation is complete, it advises placing management servers behind a Security Gateway and limiting TCP/19009 and Trusted Clients to trusted internal addresses.

WHAT TO CHECK — Inventory every management, multi-domain management, log, multi-domain log, and SmartEvent server by its running release and exact Jumbo Hotfix Take; patch or retire every affected node, then verify the service returned on the fixed build. Apply the TCP/19009 and Trusted Clients restrictions even after patching. Run Check Point's two published indicator checks across every listed server, review results for oversized usernames, matching FWM or MDS core dumps, upgrade-resource load failures, and paths containing ../, and treat a hit as a potential exploitation attempt. Preserve logs and dumps before cleanup, isolate suspect managers, and rotate administrative credentials and other secrets reachable from the management plane.

Published 22 SEP 2026Back to Daily Briefs