Check Point Zero-Day Exploited in July, Patched September 22

Check Point disclosed CVE-2026-93616, a zero-day exploited July 23 allowing unauthenticated script execution on Security Management Servers, and released a patch.
Check Point Zero-Day Exploited in July, Patched September 22
Table of Contents
    Add a header to begin generating the table of contents

    Check Point disclosed CVE-2026-93616 on September 22, 2026, a zero-day vulnerability exploited in targeted attacks on July 23 that allows unauthenticated attackers to execute scripts on Security Management Servers.

    The flaw affects the server that controls firewall policies across Check Point network deployments. An unauthenticated attacker can exploit the vulnerability through web service access to run arbitrary scripts on the management server. Check Point released a patch on September 22, two months after the initial exploitation.

    CVE-2026-93616 Exploited July 23 in Targeted Attacks

    Attackers exploited CVE-2026-93616 in targeted operations on July 23, 2026. The vulnerability allows an unauthenticated remote attacker to execute scripts on Check Point Security Management Servers by accessing the server’s web service interface.

    Check Point’s Security Management Server functions as the central control point for firewall policy administration across enterprise networks. Organizations use the management server to define, distribute, and enforce security policies on Check Point firewall appliances and gateways. Compromise of this infrastructure component grants attackers control over the firewall ruleset itself.

    Unauthenticated Web Service Exploitation Path

    The flaw resides in the management server’s web service access mechanism. No authentication is required to exploit CVE-2026-93616, meaning any attacker with network access to the management server’s web interface can trigger the vulnerability.

    Once exploited, the attacker gains the ability to execute arbitrary scripts on the management server with the privileges of the server process. This level of access enables modification of firewall policies, extraction of network configuration data, and potential pivoting to managed firewall devices.

    Two-Month Gap Between Exploitation and Disclosure

    Check Point identified exploitation of CVE-2026-93616 on July 23, 2026, but did not publicly disclose the vulnerability or release a patch until September 22, 2026. The 61-day window between detection and disclosure raises questions about notification practices for customers whose management servers may have been compromised during the silent period.

    The vendor has not stated how many organizations were affected by the July 23 attacks, whether compromised systems have been identified and remediated, or what investigative steps were taken between July and September. The disclosure timeline also does not clarify whether attackers continued to exploit the vulnerability after July 23 or whether Check Point observed additional exploitation attempts in August and early September.

    Check Point Releases Patch September 22

    Check Point released a patch for CVE-2026-93616 on September 22, 2026, concurrent with the public disclosure. The vendor advised customers to update their Security Management Servers immediately.

    The patch addresses the unauthenticated script execution flaw in the web service component. Check Point has not published a CVE severity score, technical details on the specific web service endpoint affected, or indicators of compromise for organizations seeking to determine whether their management servers were targeted.

    Organizations running Check Point Security Management Servers face a critical decision point. The vulnerability was exploited in July, meaning any unpatched management server accessible to attackers during the two-month disclosure window was at risk. Customers must apply the September 22 patch and conduct forensic review of management server logs to identify unauthorized access or policy changes between July 23 and September 22.

    Implications for Firewall Management Infrastructure Security

    CVE-2026-93616 highlights the risk concentration in centralized management infrastructure. A single unauthenticated remote code execution flaw in the management server can compromise the security posture of an entire enterprise network by granting attackers policy-level control over perimeter defenses.

    The absence of authentication requirements for exploitation compounds the severity. Organizations that expose management server web interfaces to untrusted networks—whether for remote administration, third-party integrations, or misconfigured network segmentation—face direct risk from unauthenticated attackers.

    The July-to-September disclosure gap also presents an incident response challenge. Organizations patching on September 22 must now investigate whether their management servers were compromised during the preceding two months, a forensic task complicated by the potential for attackers to modify logs or erase evidence of unauthorized policy changes. Customers with no visibility into Check Point’s July 23 discovery have limited context for scoping their internal investigations.

    Related Posts