Last week’s management CVSS 9.8 had no ITW. Today’s does.
On September 22 Check Point published an action-required blog covering two actively exploited paths. Lead item for enterprise boards: CVE-2026-93616 — a newly disclosed zero-day in Security Management. Company description: pre-authentication path traversal in the Management web service that lets an attacker execute a script from an arbitrary path and load an arbitrary Java class. Check Point scores it CVSS 9.8 and marks it In the Wild: Yes. Support article: sk1000171.
BleepingComputer (Sep 22) frames the same flaw as directory traversal + file upload enabling unauthenticated arbitrary-script execution on Management Servers, and quotes Check Point that it is “aware of a handful of customers who have been attacked.” The vendor blog is slightly more precise on timing: as of advisory publication, research observed a handful of pinpointed attacks on July 23, 2026. Victim census: “handful / pinpointed.” Successful-breach count beyond that: Undisclosed.
Affected products per Check Point / BC: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Version table on the blog (summarized): R82.20; R82.10 Jumbo Take 44 or lower; R82 Jumbo Take 126 or lower; R81.20 Jumbo Take 166 or lower; R81.10 Jumbo Take 190 or lower (EoS); and older EoS branches (R80 through R81). Critical operational note from Check Point: LivePatch Take 28/29 does not address this issue — apply the Jumbo / hotfix path in sk1000171, not assume LivePatch covered you.
Same advisory day, companion pressure: CVE-2026-85102 (CVSS 9.8) — pre-auth RCE in Security Gateway VPN certificate handling. Fix and disclosure September 9; at disclosure Check Point had no exploitation evidence. Blog now: exploitation attempts against Spark customers globally since about September 12, via anonymization infra, with observed cert subjects including CN=vpn,OU=users,O=global (list not exhaustive). Customers who already applied sk1000117 are protected. That is attempt telemetry, not a published victim roster — count of successful Spark compromises: Undisclosed.
Mitigate now, sourced: install the applicable Jumbo / Security Hotfix from sk1000171 (93616) and confirm sk1000117 (85102) on gateways/Spark if not already. Temporary hardening if the hotfix is delayed: put management behind a firewall and restrict Trusted Clients / management access (including TCP 19009 per secondary write-ups) to known IPs — Check Point and BC both push Trusted Clients allowlisting. Hunt IoCs and mitigation detail: follow sk1000171; IoCs are limited to the SK.
POV: This is a different CVE from Sep 18’s CVE-2026-91843 (no ITW at disclosure). Same plane — the box that pushes policy — now with vendor-confirmed limited ITW. Patch sk1000171 today. Verify LivePatch did not silently “cover” you. Shrink management exposure. Sources: Check Point blog Sep 22 + sk1000171 / sk1000117, BleepingComputer Sep 22.
