important · Edge — Management
Attackers exploited a pre-authentication path that executes scripts on Check Point management servers.
Affects
Check Point Security Management, Multi-Domain Management, Log Server and SmartEvent systems used to administer Check Point security infrastructure.
A client that can reach the management web service on TCP/19009 can use directory traversal and file upload to execute an arbitrary-path script or load an arbitrary Java class without credentials.
Detail and 4 sources
Check Point says a handful of customers were attacked through this path.
Sources
Researchhttps://support.checkpoint.com/results/sk/sk1000171Researchhttps://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93616.jsonVendorSecurity Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616 - Check Point BlogSecondaryhttps://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json