Critical Check Point Flaw CVE-2024-24934 Actively Exploited
Key Takeaways A critical zero-day vulnerability (CVE-2026-93616) in Check Point’s Security Management infrastructure is being actively exploited. The flaw carries a CVSS score of 9.8 and allows...
Key Takeaways
- A critical zero-day vulnerability (CVE-2026-93616) in Check Point’s Security Management infrastructure is being actively exploited.
- The flaw carries a CVSS score of 9.8 and allows unauthenticated remote code execution.
- Affected products include various Check Point Security Management Server, Log Server, and SmartEvent versions.
- Emergency fixes are available, and immediate patching is strongly recommended.
Check Point Zero-Day Actively Exploited in Management Infrastructure
Check Point has issued an urgent warning to its customers regarding active exploitation of a severe zero-day vulnerability within its Security Management infrastructure. Identified as CVE-2026-93616, this critical flaw boasts a CVSS score of 9.8, indicating maximum severity. It permits an unauthenticated attacker to remotely upload and execute arbitrary scripts on an exposed Management Server, posing a significant risk to organizational security.
Table Of Content
The cybersecurity vendor confirmed that a limited number of targeted customer attacks have been identified, prompting the immediate release of emergency patches. The vulnerability stems from a combination of directory traversal and insecure file-upload mechanisms present in the Check Point Management web service.
Exploiting this flaw, an adversary can manipulate file paths to compel the service to execute a script from an arbitrary location or load an arbitrary Java class without requiring prior authentication. This grants an external attacker the ability to run their own code on a highly privileged system responsible for administering security policies and collecting critical operational data.
Details of the Exploitation and Affected Products
Check Point characterized the observed exploitation as “pinpointed” and limited, noting that the activity predates public disclosure. The company revealed that attacks were detected on July 23, 2026, making CVE-2026-93616 a true zero-day as it was abused before a security update became available. While the vendor has not publicly identified the attackers, their objectives, specific payloads, or the organizations impacted, the urgency of the advisory underscores the severity of the threat.
A broad range of Check Point products are susceptible to this vulnerability. These include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
Specific vulnerable releases encompass R82.20; R82.10 Jumbo Hotfix Take 44 and earlier; R82 Take 126 and earlier; R81.20 Take 166 and earlier; and the end-of-support R81.10 Take 190 and earlier. Furthermore, all R80, R80.10, R80.20, R80.30, R80.40, and R81 versions are also affected.
It is important to note that Smart-1 Cloud environments are not vulnerable, as Check Point has already applied the necessary fixes. Similarly, Check Point Firewall Appliances and Check Point Spark Firewall products are unaffected by this particular issue. Administrators should not rely on LivePatch for protection, as LivePatch Takes 28 and 29 do not remediate CVE-2026-93616, and due to the nature of the correction, no LivePatch will be released.
What You Should Do
- Patch Immediately: Organizations must prioritize installing the R82.20 Security Hotfix or upgrading to a fixed Jumbo Hotfix Accumulator without delay. The corrective updates are included in R82.10 Take 45, R82 Take 127, R81.20 Take 170, and R81.10 Take 192 or later versions.
- Implement Network Segmentation: Until patching is complete, ensure that management servers are positioned behind a Security Gateway or Check Point firewall. Restrict access to TCP port 19009 exclusively to trusted IP addresses.
- Configure SmartConsole Trusted Clients: Verify that Trusted Clients configured in SmartConsole contain only trusted internal IP addresses.
- Proactive Threat Hunting: Conduct thorough threat hunting across all affected management, logging, and SmartEvent servers, regardless of whether they are internet-facing. Check Point’s advisory provides detailed Expert-mode commands for identifying unusually long usernames in cpm.elg logs and correlating these records with FWM or MDS core dumps.
- Monitor for Anomalies: Search for ReflectionUtils errors indicating a failure to load an allResourceFiles map, and examine returned paths for directory traversal sequences like “../”. Such patterns are strong indicators of exploitation attempts and warrant immediate investigation.
- Incident Response Protocol: If suspicious log entries or evidence of compromise are found, preserve all relevant logs and core dumps, isolate the affected server where operationally feasible, assess any subsequent malicious activity, and promptly contact Check Point Support.
- Stay Updated: The vendor’s latest advisory was updated on September 22, 2026. Administrators should continuously monitor it for any new indicators of compromise or revised guidance. Given that a compromised management server can grant attackers control over a central administrative plane, applying the hotfix should take precedence over relying solely on access controls.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.