← Back to Daily Briefing (#RCE)

CVE-2026-93616: Critical Unauthenticated RCE in Check Point Management Server

Published October 4, 2026

In September 2026, Check Point disclosed CVE-2026-93616, a critical unauthenticated remote code execution flaw affecting Security Management Server and Log Server versions R80.30 through R80.40 prior to hotfix CP‑HF‑2026‑09‑15. The vulnerability, scored CVSS v3.1 9.8, stems from insufficient input validation in the web‑based management interface’s file upload endpoint (/msa/upload.php), allowing an attacker to embed directory‑traversal sequences (e.g., \"../\") in the filename parameter, write arbitrary scripts outside the intended directory, and execute them with root privileges. Active exploitation has been observed in targeted attacks against high‑value enterprises, prompting emergency patches via LivePatch and advisories from Check Point, CISA, and multiple threat‑intel feeds.

  • Overview
  • Disclosed September 2026; affects Check Point Security Management Server and Log Server R80.30‑R80.40 (pre‑hotfix).
  • CVSS v3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/H:A).
  • Patched via LivePatch hotfix CP‑HF‑2026‑09‑15; full fix in R80.41.

  • Vulnerability Mechanics

  • Unauthenticated POST to /msa/upload.php with multipart/form-data.
  • Filename parameter accepts path‑traversal sequences (e.g., \"../\") allowing write outside /var/log/CPsuite/ intended upload dir.
  • Uploaded files (e.g., .sh, .py) are subsequently executed with root privileges by the management service.
  • No authentication or user interaction required; network reach to management interface suffices.

  • Impact & Exploitation Status

  • Actively exploited in targeted campaigns against enterprises; confirmed by Check Point, CISA AA26-260A, and multiple intel feeds.
  • Potential impact: full root compromise of management server, alteration of firewall policies, disabling protections, log exfiltration, lateral movement via compromised management plane.
  • Persistence mechanisms observed: cron jobs, systemd service creation, authorized_key injection.
  • Affected assets: Security Management Servers, Log Servers, Integrated SmartConsole deployments.

  • Detection & Mitigation

  • IOCs: POST to /msa/upload.php containing filename with \"../\"; creation of .sh/.py files under /var/log/CPsuite/; root‑owned processes spawned from /tmp or /var/log/CPsuite/.
  • Example YARA rule: detects multipart boundary strings and file size <1MB (provided in research).
  • Snort/Suricata signature: alerts on POST to /msa/upload.php with PCRE matching \"filename\s=\s\\"(^\\")*\.\.\//\".
  • Mitigation: apply LivePatch hotfix CP‑HF‑2026‑09‑15 immediately; restrict management interface to trusted networks; enforce MFA for SmartConsole access; monitor for anomalous file creation and process execution; review logs for upload.php anomalies.

  • Conclusion & Recommendations

  • Treat CVE-2026-93616 as a priority‑one patch; verify hotfix application via Check Point SmartUpdate or CLI.
  • Implement network segmentation: isolate management servers from untrusted zones and limit administrative access.
  • Enhance detection: deploy the provided YARA and IDS signatures, correlate upload events with privilege escalation alerts.
  • Conduct post‑compromise assessment: check for unauthorized scripts, cron entries, and key modifications if exposure suspected.
  • Maintain continuous threat‑intel subscription to track follow‑on exploits or related vulnerabilities (e.g., CVE‑2026‑85102).

Related posts

  1. Check Point Research — Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616
  2. techjacksolutions.com — CVE-2026-93616: Critical Path Traversal and Unauthenticated File Upload Vulnerability in Check Point Management Server
  3. socprime.com — CVE-2026-93616: Check Point Management Server Zero-Day Exploited in Targeted Attacks
  4. arcticwolf.com — Check Point VPN Critical RCE Vulnerabilities CVE-2026-85102 & CVE-2026-85103
  5. thehackernews.com — Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
  6. Support
  7. Beazley
  8. Esentire
  9. Aviatrix
  10. Sentinelone
  11. Esecurityplanet
  12. Vijilan
  13. Truesec
  14. Aviatrix
  15. Nvd

LINK COPIED TO CLIPBOARD