MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-22 · via BleepingComputer

Check Point rushes hotfix for critical management server flaw under active exploitation

Image via BleepingComputer
Image via BleepingComputer

Check Point Software has issued emergency patches for a critical path traversal vulnerability in its Security Management Server that allows unauthenticated attackers to upload and execute arbitrary scripts. The flaw, tracked as CVE-2026-93616, is being actively exploited in the wild, with a small number of customers already targeted. The company recommends immediate deployment of the hotfix and offers temporary mitigation steps for those unable to patch right away.

Expanded Detail

The affected products form the backbone of enterprise security administration, with the Management Server acting as the central hub for policy distribution and log aggregation across entire networks. Check Point's advisory includes indicators of compromise to help administrators detect whether attackers have already breached their systems. For organizations unable to apply the hotfix immediately, the company suggests restricting SmartConsole access to trusted IP addresses and placing vulnerable servers behind firewalls as interim safeguards.

This incident follows a pattern of recurring vulnerabilities in Check Point's infrastructure products. Recent months have seen multiple zero-days exploited in the wild, including authentication bypasses in SmartConsole and VPN gateways, with ransomware groups and affiliates among the known attackers. The Dutch NCSC recently warned that exploitation attempts for other Check Point flaws were expected imminently, underscoring the sustained attention threat actors are giving to this vendor's enterprise offerings.

Context

This vulnerability could have significant ripple effects across the many organizations that rely on Check Point's management infrastructure, since a compromised management server grants attackers control over security policies and access to sensitive network logs. Enterprises in finance, healthcare, and government may face operational disruption or data exposure if exploited. The repeated pattern of actively exploited Check Point flaws could also erode customer confidence in the vendor's products, prompting some organizations to reassess their security architecture choices and accelerate migration to alternative platforms.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
F5 issues emergency patch for BIG-IP APM zero-day under active exploitation · Cybersecurity
Critical Check Point bug grants unauthenticated root access to management servers · Cybersecurity
Arista fixes critical VeloCloud Orchestrator flaw under active attack · Cybersecurity
D-Link flags unpatched critical flaw in legacy routers with public exploit · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Check Point warns of Management Server zero-day exploited in attacks.” Browse more stories.