CVE-2026-93616
Check Point Quantum Security Management directory traversal and file upload allows unauthenticated script execution (CVE-2026-93616)
Check Point Quantum Security Management is affected by a critical directory traversal and file upload flaw (CVE-2026-93616) that lets unauthenticated attackers run arbitrary scripts. CISA KEV lists active exploitation. Apply vendor instructions in SK1000171.
What happened
Check Point Quantum Security Management contains a directory traversal and file upload vulnerability (CWE-22). An unauthenticated attacker who can reach the management server over the network can upload files to unintended locations and execute arbitrary scripts. No credentials, user interaction, or special conditions are needed; the CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, giving a score of 9.8. In practice, a remote attacker could take full control of the management server.
Check Point published SK1000171 for this issue. CISA added CVE-2026-93616 to its Known Exploited Vulnerabilities catalog on 22 September 2026, with a due date of 25 September 2026. CISA's SSVC assessment lists exploitation as active and automatable. The vendor advisory does not list a workaround.
Who is affected
The affected product is Check Point Quantum Security Management. Affected releases are:
- R82.20 with no Jumbo Hotfix
- R82.10 with Jumbo Hotfix Take 44 or below
- R82 with Jumbo Hotfix Take 126 or below
- R81.20 with Jumbo Hotfix Take 166 or below
- R81.10 (EOS) with Jumbo Hotfix Take 190 or below
- R81 (EOS)
- R80.40 (EOS)
- R80.30 (EOS)
Quantum Security Management is the central management platform for Check Point gateways. Because the flaw is network-reachable and requires no credentials, any deployment where the management interface is reachable from untrusted networks should be treated as highest priority. Several affected releases are end-of-support.
What to do now
- Confirm whether your environment runs Quantum Security Management and identify the version and Jumbo Hotfix Take.
- Apply Check Point's fix from SK1000171. Check Point has made a fix available; the advisory does not specify fixed version numbers here, so use the vendor support article to confirm the exact hotfix or version for your release.
- If you cannot apply the fix immediately, isolate the management server: restrict access to trusted management networks or VPNs, remove any internet exposure, and monitor for unauthorised changes.
- Because the vulnerability allows unauthenticated script execution, treat a reachable management server as potentially compromised until you have checked for unexpected files, scripts, accounts, or scheduled tasks and reviewed admin activity.
- Apply CISA's required action for CVE-2026-93616, including the BOD 26-04 and forensics triage guidance referenced in the KEV record if your organisation is subject to it.
How to detect it
The vendor advisory does not provide specific indicators of compromise. Because the flaw permits unauthenticated upload and execution of scripts, review the management server for unexpected script files, processes, accounts, and administrative changes. Monitor management-interface access logs for connections from unexpected sources.
Beyond the patch
An unauthenticated, network-reachable flaw on a central management server is not just a patch item: if CISA KEV is right about active exploitation, the question is whether the management interface was reachable before you patched. After applying SK1000171, make sure you have visibility over that environment. Managed Detection & Response (MDR) helps detect post-exploitation activity on the management server and connected infrastructure, and Virtual CISO Services (vCISO) can help assess whether the management interface is actually exposed to the internet and how to keep it isolated.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Quantum Security Management | R82.20 with no Jumbo Hotfix R82.10 with Jumbo Hotfix Take 44 or below R82 with Jumbo Hotfix Take 126 or below R81.20 with Jumbo Hotfix Take 166 or below R81.10 (EOS) with Jumbo Hotfix Take 190 or below R81 (EOS) R80.40 (EOS) R80.30 (EOS) | No fixed version listed yet |