CVE-2026-93616

9.8 CISA KEV

Check Point · Quantum Security Management

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on the Check Point Management Server.

Executive summary

This critical vulnerability in Check Point Quantum Security Management permits unauthenticated remote code execution and is currently being actively exploited in the wild.

Vulnerability

The flaw is a path traversal (CWE-22) that allows an unauthenticated attacker to bypass directory restrictions, perform arbitrary file uploads, and subsequently execute malicious scripts on the underlying management server.

Business impact

The ability for an unauthenticated attacker to execute arbitrary code on a security management server represents a total compromise of the security infrastructure. Given the CVSS score of 9.8, this flaw poses an extreme risk of full system takeover, data exfiltration, and lateral movement within the network. Organizations relying on this platform for policy enforcement face immediate operational and security failure if this vulnerability is not addressed.

Remediation

Immediate Action: Apply the specific Jumbo Hotfix or vendor-supplied patch as detailed in the official Check Point security advisory (SK1000171).

Proactive Monitoring: Monitor management server logs for anomalous file upload attempts, unexpected script executions, or unauthorized directory access patterns.

Compensating Controls: Restrict access to the management server interface to known, trusted administrative IP addresses and ensure the server is not exposed to the public internet.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept repository is available on GitHub.

Analyst recommendation

Due to the critical nature of this vulnerability and confirmed active exploitation, immediate patching of all affected Check Point Quantum Security Management systems is mandatory. Security teams should prioritize this update above all other maintenance activities to prevent total system compromise. If patching is not immediately feasible, ensure the management interface is physically or logically isolated from all untrusted network segments.

More Check Point CVEs

History

  1. Disclosed CVE record published
  2. Added to CISA KEV confirmed active exploitation
  3. Collected by CVE Brief via github
  4. Analyst report written
  5. Published in the daily brief kev section

Sources