The Two-Month Window

Check Point released emergency hotfixes on September 23, 2026 for CVE-2026-93616, a critical path traversal vulnerability in Check Point Security Management Server.

The vulnerability was actively exploited as far back as July 23, 2026.

Two months. That's how long threat actors had to compromise Management Servers before a patch existed.

What CVE-2026-93616 Is

CVE-2026-93616 is unauthenticated path traversal in Check Point Security Management Server allowing an attacker to upload malicious scripts and execute them on vulnerable servers. No credentials required. No authentication bypass needed. Just path traversal leading directly to arbitrary script upload and remote code execution.

Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.

The Security Management Server is the control plane for an entire Check Point deployment. It manages security policies, firewall rules, VPN configurations, admin accounts, and audit logs across every Check Point device in the enterprise. Compromise the Management Server, and you control the entire security infrastructure.

What an Attacker Can Do

An attacker with Management Server access can:

  • Modify firewall rules to allow malicious traffic through the perimeter
  • Disable logging to erase evidence of the breach
  • Extract VPN credentials for remote access to internal networks
  • Create backdoor admin accounts across all managed Check Point gateways
  • Deploy persistent backdoors on managed devices
  • Audit and exfiltrate all security policy configurations

The Management Server is a privileged control point. It's not just another server in the stack. It's the server that tells every other security device in the deployment what to do. Compromise it, and the attacker owns the security posture of the entire organization.

The Timeline

July 23, 2026: CVE-2026-93616 exploitation begins (earliest observed activity).

August 1 to September 22, 2026: Exploitation continues. Organizations running vulnerable Management Servers have no indication of compromise. Check Point has not yet disclosed the vulnerability. No patch exists. No detection signatures. No compromise indicators.

September 23, 2026: Check Point releases emergency hotfixes and discloses active exploitation dating back to July 23.

Two months of exploitation before disclosure. Two months of undetected access to the most privileged system in the Check Point deployment. Two months for threat actors to modify policies, exfiltrate credentials, deploy backdoors, and cover their tracks.

The Incident Response Problem

Organizations discovering CVE-2026-93616 compromise now face an incident response challenge that goes beyond patching.

They need to audit every security policy change made between July 23 and September 23. Every firewall rule modification. Every VPN configuration update. Every admin account creation. Every log deletion. Every system configuration change pushed from the Management Server to managed devices.

Because the Management Server controls logging, an attacker with access could have deleted or modified audit logs to hide their activity. That means organizations can't trust their own logs from the July-September window. They need to cross-reference Management Server logs with logs from managed devices, assume tampering, and treat every unexplained configuration change as potentially malicious.

Check Point released the hotfix in R82.20 Security Hotfix. For organizations unable to patch immediately, Check Point recommends restricting access to the Security Management Server by placing it behind a firewall and limiting connections to trusted IP addresses (configured under Manage & Settings, Permissions & Administrators, Trusted Clients in SmartConsole).

That's a mitigation, not a fix. And for organizations that were compromised during the July-September window, the damage is already done. The attacker had two months. Restricting access now doesn't undo what happened then.

What This Means

Zero-day vulnerabilities in management infrastructure are the worst-case scenario. The vulnerability existed before anyone knew to look for it. The exploitation happened before a patch was available. And the compromise affected the one system in the deployment that controls every other system.

Check Point Management Servers are enterprise infrastructure. They're deployed in organizations that depend on Check Point for perimeter security, VPN access, and firewall protection. Compromise one Management Server, and the attacker has a foothold in the most privileged part of the network.

The two-month exploitation window means organizations need to assume compromise and conduct forensic analysis even if they see no obvious signs of breach. Absence of evidence is not evidence of absence, especially when the compromised system is the one that writes the logs.

If your organization uses Check Point Security Management Server, patch immediately. Then begin the forensic work. Audit July-September activity. Cross-reference logs. Assume tampering. Treat every unexplained policy change as a potential attacker action. The window was two months. The attacker had that entire time to do whatever they wanted.

Check Point published the advisory on September 23, 2026. Organizations have the patch now. But they also have two months of potential compromise to investigate. That's the problem with zero-days in management infrastructure. By the time you know to check, the attacker has already been there.

Source: Check Point Blog, "Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616," September 23, 2026.