Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Check Point Flaw CVE-2024-24934 Actively Exploited
September 22, 2026
Threat Intelligence Streamlines SOC Triage, Reduces Analyst Burnout
September 22, 2026
New AI Tool Steals Credit Cards, Compromises Retailers
September 22, 2026
Home/CyberSecurity News/Critical Check Point Flaw CVE-2024-24934 Actively Exploited
CyberSecurity News

Critical Check Point Flaw CVE-2024-24934 Actively Exploited

Key Takeaways A critical zero-day vulnerability (CVE-2026-93616) in Check Point’s Security Management infrastructure is being actively exploited. The flaw carries a CVSS score of 9.8 and allows...

Emy Elsamnoudy
Emy Elsamnoudy
September 22, 2026 3 Min Read
3 0

Key Takeaways

  • A critical zero-day vulnerability (CVE-2026-93616) in Check Point’s Security Management infrastructure is being actively exploited.
  • The flaw carries a CVSS score of 9.8 and allows unauthenticated remote code execution.
  • Affected products include various Check Point Security Management Server, Log Server, and SmartEvent versions.
  • Emergency fixes are available, and immediate patching is strongly recommended.

Check Point Zero-Day Actively Exploited in Management Infrastructure

Check Point has issued an urgent warning to its customers regarding active exploitation of a severe zero-day vulnerability within its Security Management infrastructure. Identified as CVE-2026-93616, this critical flaw boasts a CVSS score of 9.8, indicating maximum severity. It permits an unauthenticated attacker to remotely upload and execute arbitrary scripts on an exposed Management Server, posing a significant risk to organizational security.

Table Of Content

  • Key Takeaways
  • Check Point Zero-Day Actively Exploited in Management Infrastructure
  • Details of the Exploitation and Affected Products
  • What You Should Do

The cybersecurity vendor confirmed that a limited number of targeted customer attacks have been identified, prompting the immediate release of emergency patches. The vulnerability stems from a combination of directory traversal and insecure file-upload mechanisms present in the Check Point Management web service.

Exploiting this flaw, an adversary can manipulate file paths to compel the service to execute a script from an arbitrary location or load an arbitrary Java class without requiring prior authentication. This grants an external attacker the ability to run their own code on a highly privileged system responsible for administering security policies and collecting critical operational data.

Details of the Exploitation and Affected Products

Check Point characterized the observed exploitation as “pinpointed” and limited, noting that the activity predates public disclosure. The company revealed that attacks were detected on July 23, 2026, making CVE-2026-93616 a true zero-day as it was abused before a security update became available. While the vendor has not publicly identified the attackers, their objectives, specific payloads, or the organizations impacted, the urgency of the advisory underscores the severity of the threat.

A broad range of Check Point products are susceptible to this vulnerability. These include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.

Specific vulnerable releases encompass R82.20; R82.10 Jumbo Hotfix Take 44 and earlier; R82 Take 126 and earlier; R81.20 Take 166 and earlier; and the end-of-support R81.10 Take 190 and earlier. Furthermore, all R80, R80.10, R80.20, R80.30, R80.40, and R81 versions are also affected.

It is important to note that Smart-1 Cloud environments are not vulnerable, as Check Point has already applied the necessary fixes. Similarly, Check Point Firewall Appliances and Check Point Spark Firewall products are unaffected by this particular issue. Administrators should not rely on LivePatch for protection, as LivePatch Takes 28 and 29 do not remediate CVE-2026-93616, and due to the nature of the correction, no LivePatch will be released.

What You Should Do

  • Patch Immediately: Organizations must prioritize installing the R82.20 Security Hotfix or upgrading to a fixed Jumbo Hotfix Accumulator without delay. The corrective updates are included in R82.10 Take 45, R82 Take 127, R81.20 Take 170, and R81.10 Take 192 or later versions.
  • Implement Network Segmentation: Until patching is complete, ensure that management servers are positioned behind a Security Gateway or Check Point firewall. Restrict access to TCP port 19009 exclusively to trusted IP addresses.
  • Configure SmartConsole Trusted Clients: Verify that Trusted Clients configured in SmartConsole contain only trusted internal IP addresses.
  • Proactive Threat Hunting: Conduct thorough threat hunting across all affected management, logging, and SmartEvent servers, regardless of whether they are internet-facing. Check Point’s advisory provides detailed Expert-mode commands for identifying unusually long usernames in cpm.elg logs and correlating these records with FWM or MDS core dumps.
  • Monitor for Anomalies: Search for ReflectionUtils errors indicating a failure to load an allResourceFiles map, and examine returned paths for directory traversal sequences like “../”. Such patterns are strong indicators of exploitation attempts and warrant immediate investigation.
  • Incident Response Protocol: If suspicious log entries or evidence of compromise are found, preserve all relevant logs and core dumps, isolate the affected server where operationally feasible, assess any subsequent malicious activity, and promptly contact Check Point Support.
  • Stay Updated: The vendor’s latest advisory was updated on September 22, 2026. Administrators should continuously monitor it for any new indicators of compromise or revised guidance. Given that a compromised management server can grant attackers control over a central administrative plane, applying the hotfix should take precedence over relying solely on access controls.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerabilityzero-day

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Threat Intelligence Streamlines SOC Triage, Reduces Analyst Burnout

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Linux KVM/arm64 Vulnerability Lets Attackers Escape VMs, Gain Host Access
September 22, 2026
New TASK#STOMP Backdoor Steals Documents and Wi-Fi Passwords via PowerShell
September 22, 2026
Critical Red Hat OpenShift Flaw (CVE-2024-XXXX) Lets Attackers Bypass PGP Checks
September 22, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us