Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, TechTalk

Check Point Patches a Zero-Day Letting Attackers Run Code on Security Management Servers Without Logging In

What Happened

Check Point released emergency fixes September 22 for CVE-2026-93616, a critical unauthenticated vulnerability carrying a CVSS score of 9.8 in its Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products. The flaw combines a directory-traversal weakness with unsafe file-upload handling in the management web service, letting an attacker outside the network cause the server to execute a script from an arbitrary location and load an arbitrary Java class, all without supplying credentials. Check Point identified targeted attacks against a small number of customers beginning July 23, meaning the vulnerability sat unpatched and under active exploitation for roughly two months before a fix became available. Affected versions span the current R82.20 release back through end-of-support builds including R81.10, and organizations running any supported or legacy version face exposure until patched. Read more from BleepingComputer.

Why This Matters for Canadian Organizations

Check Point management infrastructure sits behind the perimeter of many Canadian banks, insurers, and government networks, controlling firewall policy and collecting operational data across an organization’s entire security estate. A compromise of the management server itself hands an attacker a single point of control over every gateway it manages, a far more damaging outcome than compromising one firewall. Financial institutions under OSFI Guideline B-13 and organizations subject to PIPEDA breach-notification duties should treat exposed management infrastructure as a priority asset class, since a breach here touches policy, logs, and administrative access across an entire deployment rather than a single device. The two-month gap between first exploitation and patch availability also underscores a pattern Canadian security teams have seen repeatedly this year: vendors confirming active attacks well after adversaries found the flaw.

What to Do

Security teams running Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, or SmartEvent should apply the September 22 patch without delay, prioritizing internet-facing management interfaces. Until patched, restrict access to trusted IP addresses under Manage & Settings > Permissions & Administrators > Trusted Clients in SmartConsole, and review logs for signs of unexplained script execution or unfamiliar administrative activity predating the update. Organizations should also confirm which management-server versions they run, since several end-of-support releases remain vulnerable with no planned fix beyond the current guidance to upgrade.

Enjoy this article? Don’t forget to share.