Vulnerability report

Exploited in the wild Confirmed confidence In CISA KEV

CVE-2026-93616

Quantum Security Management Path Traversal

Checkpoint / Quantum Security Management · R82.20 with no Jumbo Hotfix

Severity
CVSS 9.8 · Critical
Confidence
Confirmed
Exploit status
Exploited in the wild
EPSS
2.4%
First observed
Last observed

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2026-93616 is an unauthenticated vulnerability affecting Checkpoint Quantum Security Management. A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute...

Is it exploited?

Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.

Who is affected?

Checkpoint / Quantum Security Management r82.20 with no jumbo hotfix.

What should we do?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Overview

Quantum Security Management Path Traversal

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

checkpoint Affected
Quantum Security Management
R82.20 with no Jumbo Hotfix R82.10 with Jumbo Hotfix Take 44 or below R82 with Jumbo Hotfix Take 126 or below R81.20 with Jumbo Hotfix Take 166 or below R81.10 (EOS) with Jumbo Hotfix Take 190 or below R81 (EOS) R80.40 (EOS) R80.30 (EOS) R80.20 (EOS) R80.10 (EOS) R80 (EOS)
Published
22 Sep 2026
Exploitation Reported
22 Sep 2026
Attack vector
Remote
Complexity
Low
Privileges
None
User interaction
None

Tags

cisa

CVE References

Exploitation evidence

Why Previdian marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

Check Point Blog

Recorded 22 Sep 2026

A trusted third party reported exploitation.

Proof of concept available

GitHub

Recorded 23 Sep 2026

Public scanner or PoC coverage increases practical exploitability.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the Previdian Pro API.

Learn about Pro API access
Source Added
Check Point Blog First 2026-09-22 13:50 UTC
CERT Polska 2026-09-22 15:22 UTC
TheHackerNews 2026-09-22 19:23 UTC
The Hacker News 2026-09-22 19:34 UTC
CISA 2026-09-22 19:50 UTC
CVE 2026-09-22 20:01 UTC
Security Affairs 2026-09-22 20:20 UTC
Qualys ThreatPROTECT 2026-09-24 05:20 UTC

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
User-Agents
Callback hosts
0
0
0

Request targets and User-Agents available in Pro. Callback host details available in Enterprise.

Scanner coverage

No scanner integrations recorded yet.

Virtual patch status

No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

No detection artifacts or sensor request patterns are available for this CVE yet.

Check back as sensor telemetry and scanner integrations are updated.

Risk and context

Severity, weaknesses, and research context

CVSS v3.1

9.8 Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

2.4%

Recent mention · Qualys ThreatPROTECT

CISA Warns of Check Point Vulnerabilities Exploited in Attacks (CVE-2026-85102 & CVE-2026-93616)

Check Point has two vulnerabilities that are being exploited in the wild, tracked as CVE-2026-85102 & CVE-2026-93616. The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerabilities to its Known Exploited Vulnerabilities Catalog, urging users to patch...

Read full advisory

All Mentions

Recent mention · Qualys ThreatPROTECT

CISA Warns of Check Point Vulnerabilities Exploited in Attacks (CVE-2026-85102 & CVE-2026-93616)

Qualys ThreatPROTECT · 24 Sep 2026

Check Point has two vulnerabilities that are being exploited in the wild, tracked as CVE-2026-85102 & CVE-2026-93616. The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerabilities to its Known Exploited Vulnerabilities Catalog, urging users to patch before September 25, 2026. CVE-2026-85102: Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN The vulnerability has a … Continue reading "CISA Warns of Check Point Vulnerabilities Exploited in Attacks (CVE-2026-85102 & CVE-2026-93616)"

Recent mention · Security Affairs

Check Point Fixes a New Actively Exploited Critical Security Flaw

Security Affairs · 22 Sep 2026

Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. The security firm bug is already being exploited. Attackers can abuse the flaw without logging in to […]

Recent mention · TheHackerNews

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

TheHackerNews · 22 Sep 2026

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point

Recent mention · CERT Polska

Krytyczna podatność w produktach firmy Check Point

CERT Polska · 22 Sep 2026

Zespół CERT Polska informuje o krytycznej podatności w produktach Check Point. Podatność jest aktywnie wykorzystywana przez atakujących.Podatność, oznaczona jako CVE-2026-93616 (CVSS 9.8), wynika z połączenia błędu typu path traversal oraz nieprawidłowej obsługi przesyłania plików. Umożliwia nieuwierzytelnionemu atakującemu umieszczenie i wykonanie dowolnych skryptów na serwerze zarządzania, co może skutkować pełnym przejęciem serwera. Istotnym warunkiem wykorzystania podatności jest dostęp do panelu zarządzania dostępnego z portu TCP/19009.Podatność dotyczy produktów Security Management...

Recent mention · Check Point Blog

Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616

Check Point Blog · 22 Sep 2026

As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements for our Firewall and Management products. This advisory addresses the active exploitation described below, and the immediate steps customers should take to protect affected systems. Check Point Research has identified active exploitation of two vulnerabilities affecting Security Gateway and Security Management: A fix for CVE-2026-85102 has been available since September 9, and customers who have applied it are already protected. CVE-2026-93616 is a...

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

nebula031/CVE-2026-93616-PoC

github · Created 2026-09-23 02:39:46 UTC · 0 stars · AI assessment 85%

Nebula-Consulting-Limited/CVE-2026-93616-PoC

github · Created 2026-09-23 02:39:46 UTC · 0 stars · AI assessment 85%

Timeline

From disclosure to observed exploitation

  1. 05:20 UTC

    KEV confirmed by Qualys ThreatPROTECT

    Exploitation attested by an external source

  2. 02:39 UTC

    Public PoC available

    Public proof-of-concept code published

  3. 20:20 UTC

    KEV confirmed by Security Affairs

    Exploitation attested by an external source

  4. 20:01 UTC

    KEV confirmed by CVE

    Exploitation attested by an external source

  5. 19:50 UTC

    Added to CISA KEV

    Listed in the CISA Known Exploited Vulnerabilities catalog

  6. 19:34 UTC

    KEV confirmed by The Hacker News

    Exploitation attested by an external source

  7. 19:23 UTC

    KEV confirmed by TheHackerNews

    Exploitation attested by an external source

  8. 15:22 UTC

    KEV confirmed by CERT Polska

    Exploitation attested by an external source

  9. 13:50 UTC

    Added to Previdian KEV Feed

    High-confidence, third-party attested exploitation

  10. 13:20 UTC

    Added to the Previdian watchlist

    Pro and Enterprise Watch users had 7 hours of early warning before CISA KEV. Also 1 hour before Previdian confirmed it as a KEV.

  11. 12:59 UTC

    CVE published

    Vulnerability disclosed publicly

  12. 11:08 UTC

    CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2026-93616

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2026-93616",
  "confidence": "Confirmed",
  "cvss_score": 9.8,
  "cvss_estimated": false,
  "epss_score": 0.02422,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": false
  },
  "sensor_telemetry": { "attempts": 0, "sensors": 0 }
}