Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Summary
Check Point has disclosed a zero-day vulnerability in its Security Management Server that was exploited in targeted attacks on July 23rd. The flaw, identified as CVE-2026-93616, allows unauthenticated attackers to execute scripts on the server via its web service. A fix for this vulnerability was released on September 22nd.
IFF Assessment
This vulnerability allows unauthenticated remote code execution, posing a significant threat to organizations relying on Check Point's Security Management Server for their firewall policies.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 25, 2026. Known ransomware use: Unknown.
Defender Context
This zero-day highlights the ongoing threat of sophisticated attacks targeting critical infrastructure components like network management servers. Defenders must remain vigilant about patching promptly once vendor advisories are released and implement robust network segmentation and monitoring to detect and prevent exploitation of such critical flaws.