Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
WiliRGasparetto
MVP Diamond
MVP Diamond

Action Required – CVE-2026-93616: Unauthenticated Script Execution and Its Impact on Check Point Man

CVE-2026-93616 requires immediate remediation: it has a CVSS score of 9.8 and active exploitation has been confirmed by Check Point. The vulnerability combines directory traversal and file upload capabilities, allowing an unauthenticated attacker to execute arbitrary scripts on the Management Server. The public advisory also describes arbitrary Java class loading. (Check Point Blog)

The risk involves a central component of the architecture: the infrastructure responsible for managing security policies, objects, and services. Compromise of this environment may extend the impact beyond the Management Server itself.

Affected Scope

According to sk1000171, the following components are affected:

  • Security Management Server and Multi-Domain Security Management Server;

  • Log Server and Multi-Domain Log Server;

  • SmartEvent.

Smart-1 Cloud has already been patched. Check Point Firewall Appliances and Spark Firewalls are not affected by this CVE. However, this does not eliminate the indirect exposure of environments that depend on a compromised Management Server.

What Exploitation Allows — and the Potential Consequences

Directory traversal allows an attacker to move beyond the directory boundaries intended by the application. When combined with file upload and script execution, the issue turns a file-handling vulnerability into code execution on the server.

Exploitation occurs before authentication: it does not require a valid administrator account. However, the attacker must have network access to the vulnerable service; therefore, restricting access to TCP/19009 is an immediate containment measure.

The confirmed impact is the arbitrary execution described in the advisory. The impacts below are potential post-compromise consequences, depending on the privileges obtained, accessible files, and server connectivity:

Component Potential impact after compromise
Security Management Access to configurations and sensitive data; modification of objects, policies, or automation; interference with management operations and policy distribution.
Multi-Domain Management Expansion of the compromise across hosted domains, depending on the level of access obtained on the system.
Log Server / Multi-Domain Log Server Reading, deletion, or modification of accessible logs; interruption of log collection and compromise of evidence integrity.
SmartEvent Interference with event correlation, visibility, and investigation.
Operating System Persistence, execution of additional tools, outbound connections, and lateral movement, depending on permissions and network segmentation.

It should not automatically be assumed that exploitation results in root execution, compromise of all domains, or immediate control of the gateways: these outcomes are not demonstrated in the referenced SK excerpt.

However, a malicious change made on the Management Server and subsequently installed on the gateways may affect traffic protection. The fact that the firewall itself is not directly vulnerable does not guarantee the integrity of policies received from a compromised Management Server.

Likewise, Management Server unavailability does not, by itself, mean an immediate interruption of all traffic forwarding on the gateways. The impact depends on the affected function and the environment's dependencies.

Versions and Fixes

The matrix below reflects the advisory as updated on September 22, 2026:

Version Reported affected range Recommended fix
R82.20 Listed as affected Specific Security Hotfix for R82.20
R82.10 JHF Take 44 or earlier JHF Take 45 or later
R82 JHF Take 126 or earlier JHF Take 127 or later
R81.20 JHF Take 166 or earlier JHF Take 170 or later
R81.10 — EoS JHF Take 190 or earlier JHF Take 192 or later
R80, R80.10, R80.20, R80.30, R80.40, and R81 — EoS Listed as affected Validate the upgrade path with Check Point Support

Do not infer protection for intermediate Takes omitted from the advisory. For R81.20 and R81.10, use the explicitly identified fixed Takes as the reference.

LivePatch Take 28/29 does not remediate this vulnerability. According to the SK, no LivePatch will be released for this issue due to the nature of the fix. The referenced Jumbo Hotfixes also include the fix for CVE-2026-91843.

Containment: Control Who Can Actually Reach TCP/19009

Restrict the port to trusted IP addresses using the security controls protecting the server. The assessment should include external exposure, internal networks, VPNs, and administrative segments.

When protection depends on a Check Point Gateway with implied rules enabled, review:

Manage & Settings → Permissions & Administrators → Trusted Clients

Limit trusted clients to the internal sources that are actually required. Review the effective policy on the protecting gateway, including implied rules, overly broad permissions, and any alternative access paths.

A large internal network should not automatically be treated as a trusted source. A compromised host within that network may still reach the vulnerable service even when the Management Server is not exposed to the Internet.

Investigation: Run the Checks on All Affected Servers

The SK provides two verification procedures. Run them in Expert mode on every Security Management Server, Multi-Domain Management Server, Log Server, Multi-Domain Log Server, and SmartEvent server.

1. Login Attempts with an Abnormally Long Username

grep -nHP "login\(loginRequest=LoginRequest\{authenticationInfo=AuthenticationInfoBase\{username='[^' ]{1001,}'" "$MDS_FWDIR"/log/cpm.elg*

If results are returned, check for FWM/MDS dumps:

ls -l /var/log/dump/usermode/ | grep -e fwm -e mds

Correlate the timestamp of the login attempt with the dump. According to the advisory, a matching timestamp indicates a possible exploitation attempt; by itself, it does not prove successful code execution.

2. Loading Failures Involving Suspicious Paths

grep -E "ERROR.*upgrade\.base\.ReflectionUtils.*Failed to load allResourceFiles map from" $MDS_FWDIR/log/cpm.elg*

Investigate the returned paths, especially traversal sequences such as ../. The SK example contains a path that escapes the expected directory and references files under /tmp.

Any result must be analyzed in context. The absence of results also does not prove that the system was not compromised: log retention, rotation, compressed files not examined by these commands, and possible log tampering limit the coverage of these checks.

Read errors, an incorrect environment variable, or missing expected files invalidate the verification and must not be interpreted as a negative result.

If Indicators Are Found, Treat the Situation as an Incident

In addition to containing access and applying the fix:

  • Preserve logs, dumps, and suspicious artifacts, maintaining timestamps and hashes whenever possible.

  • Correlate events with network connections, processes, created files, and persistence mechanisms.

  • Review administrative changes, policy publications, and policy installations during the investigated period.

  • Assess the potential exposure of credentials, keys, and other secrets accessible from the server.

  • Engage Check Point Support/Incident Response to determine the scope of compromise and the appropriate recovery strategy.

Applying the hotfix fixes the vulnerability, but it does not remove persistence or malicious artifacts that may already have been implanted, nor does it restore the integrity of a compromised system.

The investigation should also not begin only from the publication date: Check Point reported isolated attacks observed on July 23, 2026. This date provides a reference point for historical review, but it should not be considered an absolute boundary for the investigation. (Check Point Blog)

The operational priority is to restrict exposure, apply the supported fix, and investigate in parallel. For Management Servers, the objective also includes restoring confidence in the configurations, policies, and evidence used to protect the environment.

1 Reply
Mark89
Explorer

Do you think we should run a scan on our Manage server in addition to the fix or will the hotfix alone resolve the issue?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events