Vulnerability Intelligence Report
Directory Traversal and File upload allows execution of arbitrary script on the Management Server
CVE-2026-93616
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
CISA KEV
SSVC: Active Exploitation
Automatable
Path Traversal
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal').
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| checkpoint | Quantum Security Management | R82.20 with no Jumbo Hotfix (affected), R82.10 with Jumbo Hotfix Take 44 or below (affected), R82 with Jumbo Hotfix Take 126 or below (affected), R81.20 with Jumbo Hotfix Take 166 or below (affected), R81.10 (EOS) with Jumbo Hotfix Take 190 or below (affected), R81 (EOS) (affected), R80.40 (EOS) (affected), R80.30 (EOS) (affected), R80.20 (EOS) (affected), R80.10 (EOS) (affected), R80 (EOS) (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Check Point Software Ltd. · Vendor · Israel |
| Reserved | 2026-09-18T11:08:38 |
| Published | 2026-09-22T12:59:01 |
| Last Updated | 2026-09-22T19:58:24 |
Community Chatter & Buzz