Skip to finding
important · Edge — Management

Attackers exploited a pre-authentication path that executes scripts on Check Point management servers.

Affects

Check Point Security Management, Multi-Domain Management, Log Server and SmartEvent systems used to administer Check Point security infrastructure.

A client that can reach the management web service on TCP/19009 can use directory traversal and file upload to execute an arbitrary-path script or load an arbitrary Java class without credentials.

Detail and 4 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 23, 2026