What happened
On September 22, 2026, Check Point disclosed CVE-2026-93616, said it had seen a handful of pinpointed attacks on July 23, 2026, and released fixes. CVE-2026-93616 is a CVSS 9.8 pre-authentication path-traversal and file-upload flaw affecting Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent. Check Point says an unauthenticated attacker can upload and execute arbitrary scripts on a vulnerable management server, placing the central policy and logging plane directly at risk.
Starting September 12, 2026, Check Point observed exploitation attempts against Spark customers for CVE-2026-85102, whose fix had been available since September 9, 2026. Affected CVE-2026-93616 builds include R82.20, R82.10 Jumbo Hotfix Take 44 or lower, R82 Jumbo Hotfix Take 126 or lower, R81.20 Jumbo Hotfix Take 166 or lower and R81.10 Jumbo Hotfix Take 190 or lower; LivePatch Take 28/29 does not fix it. Fixed releases include R82.10 Take 45, R82 Take 127, R81.20 Take 170 and R81.10 Take 192, alongside the R82.20 Security Hotfix.
Check Point says access to TCP/19009 should be restricted to trusted IP addresses and Trusted Clients should be limited to trusted internal IP addresses. Check Point published an Expert-mode grep check for usernames longer than 1,000 characters in $MDS_FWDIR/log/cpm.elg files as an indication-of-compromise test for CVE-2026-93616. For CVE-2026-85102, Check Point observed certificate subjects CN=vpn,OU=users,O=global; CN=vpn-user,OU=users,O=global; and CN=vpnuser,OU=users,O=global, while warning that the list is not exhaustive. Attribution posture: Check Point named no threat actor for either exploitation cluster.
Why this matters now
Security Management Server and related products are privileged policy, logging and administrative systems. Successful pre-authentication code execution there can undermine the trustworthiness of firewall policy, administrator activity and the evidence defenders need to reconstruct an intrusion. The placement is therefore more consequential than an ordinary application-server defect, even before broader victim reporting emerges.
Check Point has supplied fixes, affected-build thresholds, interim network restrictions and compromise checks. That shifts accountability from advisory monitoring to execution: infrastructure owners must identify every affected deployment, incident response must preserve and examine management telemetry, and change authorities must explicitly disposition any system that cannot be updated immediately.
The two vulnerabilities require different review paths. CVE-2026-93616 concerns management infrastructure and known customer attacks, while CVE-2026-85102 affects VPN certificate handling on gateways and Spark firewalls. Combining them into one leadership decision is appropriate only at the governance layer; technical teams must retain separate asset, evidence and remediation records.
The decision for security leaders
Run this as a potential control-plane incident, not a routine vulnerability ticket. The security-management environment governs policy and records administrative activity; evidence collection must therefore precede changes that could overwrite logs, remove artefacts or impair later reconstruction.
Separate remediation status from compromise status. A fixed build proves that a vulnerable code path was removed; it does not establish whether the system was accessed before the update. Incident response should own the evidence-based disposition, with infrastructure teams supplying configuration and version proof.
Use emergency change authority where necessary, but do not let urgency erase operational discipline. Record pre-change state, hotfix source, post-change build, management reachability and service health. Any delay requires a named approver, compensating controls and a time-bounded remediation commitment.
Evidence of closure
- CMDB export accounts for every Check Point management, logging, SmartEvent, gateway and Spark deployment.
- Post-change evidence shows each affected system running a fixed or vendor-approved replacement release.
- Firewall evidence confirms TCP/19009 and Trusted Clients are limited to approved administrative sources.
- Incident report records completed vendor compromise checks and the disposition of every exposed system.
The Security.io assessment
This ranks first because the newly disclosed exploitation reaches both perimeter gateways and the privileged systems used to manage security policy and logs. The combination creates a more immediate enterprise decision than the other selected developments: organisations must protect the management plane while determining whether its evidence and policy state can still be trusted.
The available evidence confirms exploitation but does not establish broad victim scope, actor identity or a uniform post-exploitation sequence. A handful of reported management-server attacks should not be generalised into universal compromise, yet the absence of public victim volume does not justify delaying asset identification or evidence preservation.
Closure requires more than a successful installer result. A defensible outcome combines an authoritative asset inventory, fixed builds, constrained management exposure, completed vendor compromise checks, reviewed administrator activity and an incident-response conclusion for every exposed system. Exceptions should remain visible to the CISO until those elements are complete.
Questions for the morning meeting
- Can the infrastructure team produce an authoritative inventory of every affected Check Point management and Spark deployment?
- Who can approve emergency hotfixing where management-plane change freezes or availability concerns create delay?
- Has incident response accepted ownership of compromise review rather than treating successful patch installation as closure?
- Are management interfaces and TCP/19009 restricted to named administrative networks and trusted clients?