Threat Landscape

Check Point CVE-2026-93616 is CVSS 9.8. Management 0-day — and it is ITW.

CVE-2026-93616 (CVSS 9.8): pre-auth path traversal in the Management web service → arbitrary-path script execution + Java class load. Check Point: handful of pinpointed attacks (observed Jul 23). Fix sk1000171 today. LivePatch Take 28/29 does not fix it. Companion: CVE-2026-85102 Spark/VPN RCE now seeing exploitation attempts (patch since Sep 9).

Sep 22, 2026 · 3 min read

Last week’s management CVSS 9.8 had no ITW. Today’s does.

On September 22 Check Point published an action-required blog covering two actively exploited paths. Lead item for enterprise boards: CVE-2026-93616 — a newly disclosed zero-day in Security Management. Company description: pre-authentication path traversal in the Management web service that lets an attacker execute a script from an arbitrary path and load an arbitrary Java class. Check Point scores it CVSS 9.8 and marks it In the Wild: Yes. Support article: sk1000171.

BleepingComputer (Sep 22) frames the same flaw as directory traversal + file upload enabling unauthenticated arbitrary-script execution on Management Servers, and quotes Check Point that it is “aware of a handful of customers who have been attacked.” The vendor blog is slightly more precise on timing: as of advisory publication, research observed a handful of pinpointed attacks on July 23, 2026. Victim census: “handful / pinpointed.” Successful-breach count beyond that: Undisclosed.

Affected products per Check Point / BC: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Version table on the blog (summarized): R82.20; R82.10 Jumbo Take 44 or lower; R82 Jumbo Take 126 or lower; R81.20 Jumbo Take 166 or lower; R81.10 Jumbo Take 190 or lower (EoS); and older EoS branches (R80 through R81). Critical operational note from Check Point: LivePatch Take 28/29 does not address this issue — apply the Jumbo / hotfix path in sk1000171, not assume LivePatch covered you.

Same advisory day, companion pressure: CVE-2026-85102 (CVSS 9.8) — pre-auth RCE in Security Gateway VPN certificate handling. Fix and disclosure September 9; at disclosure Check Point had no exploitation evidence. Blog now: exploitation attempts against Spark customers globally since about September 12, via anonymization infra, with observed cert subjects including CN=vpn,OU=users,O=global (list not exhaustive). Customers who already applied sk1000117 are protected. That is attempt telemetry, not a published victim roster — count of successful Spark compromises: Undisclosed.

Mitigate now, sourced: install the applicable Jumbo / Security Hotfix from sk1000171 (93616) and confirm sk1000117 (85102) on gateways/Spark if not already. Temporary hardening if the hotfix is delayed: put management behind a firewall and restrict Trusted Clients / management access (including TCP 19009 per secondary write-ups) to known IPs — Check Point and BC both push Trusted Clients allowlisting. Hunt IoCs and mitigation detail: follow sk1000171; IoCs are limited to the SK.

POV: This is a different CVE from Sep 18’s CVE-2026-91843 (no ITW at disclosure). Same plane — the box that pushes policy — now with vendor-confirmed limited ITW. Patch sk1000171 today. Verify LivePatch did not silently “cover” you. Shrink management exposure. Sources: Check Point blog Sep 22 + sk1000171 / sk1000117, BleepingComputer Sep 22.

Sources