## Overview
CISA added CVE-2026-93616 to its Known Exploited Vulnerabilities (KEV) list on September 22, 2026. This addition signals an urgent need for organizations to address the vulnerability due to evidence of active exploitation. The vulnerability affects Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
## Technical Details
CVE-2026-93616 is a directory traversal and file upload vulnerability. It allows an unauthenticated attacker to upload and execute arbitrary scripts on the affected Check Point Management Servers. The flaw arises from improper validation of user-supplied input, permitting attackers to manipulate file paths. As a result, they can upload malicious scripts that could compromise the server.
## Impact
The vulnerability has a CVSS score of 9.8, indicating a critical risk. Successful exploitation could lead to unauthorized access, data breaches, and potential complete system compromise. Organizations using affected Check Point products are at significant risk, especially if they have not implemented adequate security measures.
## Mitigation
Defenders should prioritize applying patches provided by Check Point. Organizations must review their configurations and ensure that all instances of the affected products are updated. Additionally, monitoring for unusual activity and implementing network segmentation can help mitigate potential exploitation until patches are applied.
CSURFACE Threat Sensor