What it is
CVE-2026-93616 is an unauthenticated vulnerability affecting Checkpoint Quantum Security Management. A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute...
Vulnerability report
Quantum Security Management Path Traversal
Checkpoint / Quantum Security Management · R82.20 with no Jumbo Hotfix
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-93616 is an unauthenticated vulnerability affecting Checkpoint Quantum Security Management. A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Checkpoint / Quantum Security Management r82.20 with no jumbo hotfix.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Check Point Blog
A trusted third party reported exploitation.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Check Point Blog First | 2026-09-22 13:50 UTC |
| CERT Polska | 2026-09-22 15:22 UTC |
| TheHackerNews | 2026-09-22 19:23 UTC |
| The Hacker News | 2026-09-22 19:34 UTC |
| CISA | 2026-09-22 19:50 UTC |
| CVE | 2026-09-22 20:01 UTC |
| Security Affairs | 2026-09-22 20:20 UTC |
| Qualys ThreatPROTECT | 2026-09-24 05:20 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.4%
Recent mention · Qualys ThreatPROTECT
Check Point has two vulnerabilities that are being exploited in the wild, tracked as CVE-2026-85102 & CVE-2026-93616. The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerabilities to its Known Exploited Vulnerabilities Catalog, urging users to patch...
Read full advisoryRecent mention · Qualys ThreatPROTECT
CISA Warns of Check Point Vulnerabilities Exploited in Attacks (CVE-2026-85102 & CVE-2026-93616)Qualys ThreatPROTECT · 24 Sep 2026
Check Point has two vulnerabilities that are being exploited in the wild, tracked as CVE-2026-85102 & CVE-2026-93616. The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerabilities to its Known Exploited Vulnerabilities Catalog, urging users to patch before September 25, 2026. CVE-2026-85102: Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN The vulnerability has a … Continue reading "CISA Warns of Check Point Vulnerabilities Exploited in Attacks (CVE-2026-85102 & CVE-2026-93616)"
Recent mention · Security Affairs
Check Point Fixes a New Actively Exploited Critical Security FlawSecurity Affairs · 22 Sep 2026
Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. The security firm bug is already being exploited. Attackers can abuse the flaw without logging in to […]
Recent mention · TheHackerNews
Check Point Warns of Management Server Zero-Day Exploited in Targeted AttacksTheHackerNews · 22 Sep 2026
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point
Recent mention · CERT Polska
Krytyczna podatność w produktach firmy Check PointCERT Polska · 22 Sep 2026
Zespół CERT Polska informuje o krytycznej podatności w produktach Check Point. Podatność jest aktywnie wykorzystywana przez atakujących.Podatność, oznaczona jako CVE-2026-93616 (CVSS 9.8), wynika z połączenia błędu typu path traversal oraz nieprawidłowej obsługi przesyłania plików. Umożliwia nieuwierzytelnionemu atakującemu umieszczenie i wykonanie dowolnych skryptów na serwerze zarządzania, co może skutkować pełnym przejęciem serwera. Istotnym warunkiem wykorzystania podatności jest dostęp do panelu zarządzania dostępnego z portu TCP/19009.Podatność dotyczy produktów Security Management...
Recent mention · Check Point Blog
Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616Check Point Blog · 22 Sep 2026
As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements for our Firewall and Management products. This advisory addresses the active exploitation described below, and the immediate steps customers should take to protect affected systems. Check Point Research has identified active exploitation of two vulnerabilities affecting Security Gateway and Security Management: A fix for CVE-2026-85102 has been available since September 9, and customers who have applied it are already protected. CVE-2026-93616 is a...
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-09-23 02:39:46 UTC · 0 stars · AI assessment 85%
github · Created 2026-09-23 02:39:46 UTC · 0 stars · AI assessment 85%
Timeline
05:20 UTC
Exploitation attested by an external source
02:39 UTC
Public proof-of-concept code published
20:20 UTC
Exploitation attested by an external source
20:01 UTC
Exploitation attested by an external source
19:50 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
19:34 UTC
Exploitation attested by an external source
19:23 UTC
Exploitation attested by an external source
15:22 UTC
Exploitation attested by an external source
13:50 UTC
High-confidence, third-party attested exploitation
13:20 UTC
Pro and Enterprise Watch users had 7 hours of early warning before CISA KEV. Also 1 hour before Previdian confirmed it as a KEV.
12:59 UTC
Vulnerability disclosed publicly
11:08 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-93616
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-93616",
"confidence": "Confirmed",
"cvss_score": 9.8,
"cvss_estimated": false,
"epss_score": 0.02422,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}