Web_Logo
Remote Support
Security Alert: Check Point Server Flaw Under Active Attack
Home » Security Alerts  »  Security Alert: Check Point Server Flaw Under Active Attack

Security Alert: Check Point Server Flaw Under Active Attack

Check Point has issued an emergency fix for a critical flaw in its Management Server software, after confirming attackers are already exploiting it in the wild.

  • What it is: A vulnerability (CVE-2026-93616) lets an attacker upload and run malicious code on the server without needing to log in first.
  • Who is affected: Organisations running Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server or SmartEvent.
  • What the risk is: This server controls firewall policy, admin activity and logs across a Check Point deployment, so a compromise can expose an entire network.
  • What action is needed: Apply the R82.20 Security Hotfix Check Point released on 22 September 2026 as soon as possible.

If your business runs Check Point firewalls, we recommend checking with your IT provider that this hotfix has been applied without delay.