CVE-2026-93616
Directory Traversal and File upload allows execution of arbitrary script on the Management Server
Severity
Critical 9.8
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Sep 22, 2026
EPSS
0.024
83.5th percentile
Discovered by
Not disclosed
Published
Sep 22, 2026
Assigned by checkpoint
Description
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
Weakness: CWE-22
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Check Point | Quantum Security Management | Network & Security Management | cna-assigner |
Vendor-reported products (1)
- checkpoint · Quantum Security Management
References
- https://support.checkpoint.com/results/sk/sk1000171
- https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93616