CVE-2026-93616: Check Point Multiple Products Path Traversal Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-09-22. EPSS: 19.7% chance of exploitation in the next 30 days.
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
Affected products
- Check Point Multi-Domain Security Management: from r80, before r81.10 (fixed in r81.10); version r81.10 only; version r81.20 only; version r82 only; version r82.10 only; version r82.20 only
- Check Point Quantum Security Management: from r80, before r81.10 (fixed in r81.10); version r81.10 only; version r81.20 only; version r82 only; version r82.10 only; version r82.20 only
Published 2026-09-22. Last modified 2026-09-23.