<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [Action required] Critical Vulnerability CVE-2026-93616 in Check Point Security Management CVSS in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Action-required-Critical-Vulnerability-CVE-2026-93616-in-Check/m-p/282767#M47116</link>
    <description>&lt;P&gt;It's always a good idea to make sure you weren't compromised.&lt;BR /&gt;The patch will prevent compromises related to this CVE, as will ensuring you follow the hardening guidelines.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Sep 2026 14:28:49 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2026-09-24T14:28:49Z</dc:date>
    <item>
      <title>[Action required] Critical Vulnerability CVE-2026-93616 in Check Point Security Management CVSS 9.8</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Action-required-Critical-Vulnerability-CVE-2026-93616-in-Check/m-p/282631#M47090</link>
      <description>&lt;DIV id="x_mail-editor-reference-message-container"&gt;
&lt;DIV id="x_mail-editor-reference-message-body"&gt;
&lt;DIV data-olk-copy-source="MailCompose"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV data-olk-copy-source="MailCompose"&gt;&lt;FONT size="4"&gt;Check Point has released a fix for &lt;A id="OWA2c203609-ce3f-f2c1-2ffa-ac8d800f7451" class="OWAAutoLink" title="https://support.checkpoint.com/results/sk/sk1000171" href="https://support.checkpoint.com/results/sk/sk1000171" target="_blank" rel="noopener" data-outlook-id="d672146b-e664-4f1b-bc75-e6e7850debb5" data-auth="NotApplicable"&gt;CVE-2026-93616&lt;/A&gt;, a critical vulnerability (CVSS 9.8) that allows an &lt;SPAN data-teams="true"&gt;unauthenticated attacker&amp;nbsp;&lt;/SPAN&gt;to upload and execute arbitrary scripts on Security Management servers. Exploitation has been observed in the wild, and to date only a handful of customers are known to have been attacked.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size="4"&gt;Affected products include Security Management, Log Server, Multi-Domain Management, and Multi-Domain Log Server.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size="4"&gt;Note: Quantum Force and Quantum Spark firewalls are not affected, and Smart-1 Cloud is already patched.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size="4"&gt;What we ask you to do now:&lt;/FONT&gt;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV role="presentation"&gt;&lt;FONT size="4"&gt;&lt;SPAN&gt;Upgrade&lt;/SPAN&gt; to the latest Jumbo Hotfix for your release:&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;UL data-editing-info="{&amp;quot;applyListStyleFromLevel&amp;quot;:true}"&gt;
&lt;LI&gt;
&lt;DIV role="presentation"&gt;&lt;FONT size="4"&gt;R82.10 JHF Take 45&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV role="presentation"&gt;&lt;FONT size="4"&gt;R82 JHF Take 127&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV role="presentation"&gt;&lt;FONT size="4"&gt;R81.20 JHF Take 170&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV role="presentation"&gt;&lt;FONT size="4"&gt;R81.10 JHF Take 192&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV role="presentation"&gt;&lt;FONT size="4"&gt;&lt;SPAN&gt;For R82.20 Customers - install available HF - R82.20 Security Hot Fix Take 1&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;
&lt;DIV role="presentation"&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: a LivePatch is not available for this issue.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV role="presentation"&gt;&lt;FONT size="4"&gt;&lt;SPAN&gt;Restrict management access&lt;/SPAN&gt; so that port 19009/tcp is reachable only from trusted IPs, per our &lt;A id="OWA3b7399a2-cdc4-d8e0-1efe-57c43f3920ab" class="OWAAutoLink" href="https://sc1.checkpoint.com/documents/Check_Point_Gateway_and_Management_Hardening/Hardening_GW_and_MGMT/Management-Plane-Protection.html" target="_blank" rel="noopener" data-outlook-id="17696fc7-97c4-4aad-bed1-a1f61a8a9124" data-auth="NotApplicable"&gt;hardening best practices&lt;/A&gt;.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size="4"&gt;&lt;SPAN&gt;Check for compromise&lt;/SPAN&gt; using the detection steps in the advisory.&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size="4"&gt;Full details, affected versions, mitigation steps, and indicators of compromise are available in &lt;SPAN&gt;&lt;A id="OWA084792ac-9970-3b4d-5b16-e3da82abd839" class="OWAAutoLink" title="https://support.checkpoint.com/results/sk/sk1000171" href="https://support.checkpoint.com/results/sk/sk1000171" target="_blank" rel="noopener" data-outlook-id="e2ac8c06-1ab2-4064-b9f9-0db212414215" data-auth="NotApplicable"&gt;sk1000171&lt;/A&gt;&lt;/SPAN&gt;. Please review it and act promptly.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size="4"&gt;To receive future security alerts directly, enable Security Alerts under My Subscriptions on the Check Point support site.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 22 Sep 2026 13:30:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Action-required-Critical-Vulnerability-CVE-2026-93616-in-Check/m-p/282631#M47090</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2026-09-22T13:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] Critical Vulnerability CVE-2026-93616 in Check Point Security Management CVSS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Action-required-Critical-Vulnerability-CVE-2026-93616-in-Check/m-p/282655#M47091</link>
      <description>&lt;P&gt;Because it will be asked: Standalone firewalls (i.e. management and firewall on same device) ARE affected by this and should be patched/remediated.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 15:37:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Action-required-Critical-Vulnerability-CVE-2026-93616-in-Check/m-p/282655#M47091</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-09-22T15:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] Critical Vulnerability CVE-2026-93616 in Check Point Security Management CVSS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Action-required-Critical-Vulnerability-CVE-2026-93616-in-Check/m-p/282665#M47093</link>
      <description>&lt;P&gt;Do you think we should run a scan on our Manage server in addition to the fix or will the hotfix alone resolve the issue?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2026 20:39:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Action-required-Critical-Vulnerability-CVE-2026-93616-in-Check/m-p/282665#M47093</guid>
      <dc:creator>Mark89</dc:creator>
      <dc:date>2026-09-22T20:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] Critical Vulnerability CVE-2026-93616 in Check Point Security Management CVSS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Action-required-Critical-Vulnerability-CVE-2026-93616-in-Check/m-p/282767#M47116</link>
      <description>&lt;P&gt;It's always a good idea to make sure you weren't compromised.&lt;BR /&gt;The patch will prevent compromises related to this CVE, as will ensuring you follow the hardening guidelines.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 14:28:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Action-required-Critical-Vulnerability-CVE-2026-93616-in-Check/m-p/282767#M47116</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-09-24T14:28:49Z</dc:date>
    </item>
  </channel>
</rss>

