Web_Logo
Remote Support
Security Alert: Check Point Management Server Zero-Day
Home » Security Alerts  »  Security Alert: Check Point Management Server Zero-Day

Security Alert: Check Point Management Server Zero-Day

A serious security flaw in Check Point's network management software is being actively exploited by attackers, with a small number of confirmed victims already affected.

  • What it is: A path traversal vulnerability (CVE-2026-93616) in Check Point's Security Management Server, Multi-Domain Security Management Server, Log Server and SmartEvent products, which lets an unauthenticated attacker upload and run malicious code.
  • Who is affected: Organisations running Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server or SmartEvent.
  • What the risk is: Attackers do not need valid login credentials to exploit this flaw, and Check Point has confirmed real-world attacks are already occurring.
  • What to do: Apply the R82.20 Security Hotfix as soon as possible. If immediate patching is not possible, restrict management access to trusted IP addresses behind a firewall and watch for unexpected "administrator failed to log in" entries in your audit logs.

If your business relies on Check Point for network security, we recommend confirming with your IT provider today that this hotfix has been applied.

Source: BleepingComputer