Check Point Management Server 0-Day Vulnerability Actively Exploited in Attacks
Brief
Check Point has warned customers that attackers are exploiting a critical zero-day vulnerability in its Security Management infrastructure. Tracked as CVE-2026-93616 , the flaw carries a CVSS score of 9. 8 and enables an unauthenticated remote attacker to upload and execute arbitrary scripts on an exposed Management Server.
Check Point says it has identified a handful of targeted customer attacks and has released emergency fixes. The vulnerability combines directory traversal with unsafe file-upload behavior in the Check Point Management web service .
By manipulating file paths, an attacker can cause the service to execute a script from an arbitrary location and load an arbitrary Java class without first authenticating.
