Close Menu
NCIJ Network NCIJ Network
    What's Hot

    It’s easy to ignore the Lib Dems, but they could soon hold the balance of power | Rafael Behr

    September 23, 2026

    Trump rallies Shield of the Americas coalition against drug cartels | United Nations News

    September 23, 2026

    Das Neukölln-Problem der Linken – POLITICO

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • It’s easy to ignore the Lib Dems, but they could soon hold the balance of power | Rafael Behr
    • Trump rallies Shield of the Americas coalition against drug cartels | United Nations News
    • Das Neukölln-Problem der Linken – POLITICO
    • Critics of UK government’s economic forecaster are ‘shooting the messenger’, say MPs | Office for Budget Responsibility
    • Burnham navigates diplomatic rapids in first Trump meeting, but turbulent waters lie ahead | Andy Burnham
    • Diesel surge costs European drivers €203mn per day
    • ‘We’re already fighting yesterday’s battle’: Greece’s prime minister gets candid about AI
    • OpenAI Releases GPT-6 Sol and Luna: 50% Cheaper API Pricing and Benchmarks
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Check Point warns of Management Server zero-day exploited in attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 23, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts.

    The Security Management Server is a central repository that stores and manages security policies, processes administrator changes, and collects system logs across enterprise networks.

    Tracked as CVE-2026-93616, this path traversal flaw lets unauthenticated threat actors upload arbitrary scripts on vulnerable Check Point Management Servers and execute them in low-complexity attacks.

    The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have urged software companies since May 2024 to remove path traversal weaknesses from their products before shipping, saying such security issues “have been called ‘unforgivable’ since at least 2007.”

    Check Point has addressed the vulnerability in R82.20 Security Hotfix and said that the complete list of affected products includes Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.

    “This vulnerability is exploited in the wild. Check Point is aware of a handful of customers who have been attacked,” the company warned, while advising security teams to check their networks for evidence of successful exploitation using the indicators of compromise shared in this security advisory.

    Check Point also provides temporary mitigation measures for customers who can’t immediately deploy the hotfix on vulnerable systems, including hardening vulnerable systems against attacks by placing them behind a firewall and limiting access to trusted IP addresses from Manage & Settings > Permissions & Administrators > Trusted Clients in the SmartConsole dashboard.

    Editing Trusted Clients rules in SmartConsole
    Editing Trusted Clients rules in SmartConsole (Check Point Software)

    In recent months, Check Point has warned customers that other flaws were being actively exploited in the wild.

    For instance, two years ago, CISA flagged a flaw (CVE-2024-24919) in Check Point’s Quantum Security Gateways as actively exploited by ransomware gangs, confirming an Orange Cyberdefense CERT report linking these attacks to NailaoLocker ransomware.

    Qilin ransomware affiliate has also exploited an authentication bypass (CVE-2026-50751) zero-day since June, while a second auth bypass zero-day (CVE-2026-16232) has been exploited since at least July to authenticate with administrator privileges to SmartConsole admin panels.

    Two weeks ago, the Dutch National Cyber Security Centre (NCSC-NL) also warned organizations to urgently patch two critical Check Point VPN flaws (CVE-2026-85102 and CVE-2026-85103) because it “expects exploitation attempts to occur soon.”

    More recently, on Friday, Check Point released security updates to address another critical authentication bypass (CVE-2026-16232) in the login process for Security Management Server and Security Gateways that lets attackers execute code with root privileges on management systems.

    While the company has not yet flagged CVE-2026-16232 as actively exploited, it said security teams can identify attacks by looking for “Administrator failed to log in: Username too long” alerts in the Audit and Admin login logs.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    attacks check Exploited management Point server warns ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

    Only 13% of OT Network Segments Are Fully Isolated: Analysis

    ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

    Sweden fines Miljödata $183,000 over breach affecting 2.2 million

    Rogue external MFA providers can steal passwords during logins

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    It’s easy to ignore the Lib Dems, but they could soon hold the balance of power | Rafael Behr

    September 23, 2026

    Trump rallies Shield of the Americas coalition against drug cartels | United Nations News

    September 23, 2026

    Das Neukölln-Problem der Linken – POLITICO

    September 23, 2026

    Critics of UK government’s economic forecaster are ‘shooting the messenger’, say MPs | Office for Budget Responsibility

    September 23, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    It’s easy to ignore the Lib Dems, but they could soon hold the balance of power | Rafael Behr

    September 23, 2026

    Trump rallies Shield of the Americas coalition against drug cartels | United Nations News

    September 23, 2026

    Das Neukölln-Problem der Linken – POLITICO

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.