Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
_Val_
Admin
Admin

[Action required] Critical Vulnerability CVE-2026-93616 in Check Point Security Management CVSS 9.8

 
Check Point has released a fix for CVE-2026-93616, a critical vulnerability (CVSS 9.8) that allows an unauthenticated attacker to upload and execute arbitrary scripts on Security Management servers. Exploitation has been observed in the wild, and to date only a handful of customers are known to have been attacked.
Affected products include Security Management, Log Server, Multi-Domain Management, and Multi-Domain Log Server.
Note: Quantum Force and Quantum Spark firewalls are not affected, and Smart-1 Cloud is already patched.
 
What we ask you to do now:
  • Upgrade to the latest Jumbo Hotfix for your release:
    • R82.10 JHF Take 45
    • R82 JHF Take 127
    • R81.20 JHF Take 170
    • R81.10 JHF Take 192
    • For R82.20 Customers - install available HF - R82.20 Security Hot Fix Take 1
  • Note: a LivePatch is not available for this issue.
  • Restrict management access so that port 19009/tcp is reachable only from trusted IPs, per our hardening best practices.
  • Check for compromise using the detection steps in the advisory.
 
Full details, affected versions, mitigation steps, and indicators of compromise are available in sk1000171. Please review it and act promptly.
To receive future security alerts directly, enable Security Alerts under My Subscriptions on the Check Point support site.
3 Replies
PhoneBoy
Admin
Admin

Because it will be asked: Standalone firewalls (i.e. management and firewall on same device) ARE affected by this and should be patched/remediated.

0 Kudos
Mark89
Explorer

Do you think we should run a scan on our Manage server in addition to the fix or will the hotfix alone resolve the issue?

0 Kudos
PhoneBoy
Admin
Admin

It's always a good idea to make sure you weren't compromised.
The patch will prevent compromises related to this CVE, as will ensuring you follow the hardening guidelines.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events