Check Point Software has released emergency hotfixes for a critical vulnerability in its Security Management Server that could allow attackers to upload and run malicious scripts.
Tracked as CVE-2026-93616, the path traversal flaw can be exploited by unauthenticated attackers to upload arbitrary scripts and execute them on vulnerable systems. Check Point says the attacks are low-complexity and that the vulnerability is already being exploited in the wild.
The company said it is aware of attacks against a small number of customers and urged security teams to check their networks for signs of compromise.
The vulnerability affects several Check Point products, including Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
Check Point has fixed the issue in the R82.20 Security Hotfix. Customers that can't install the update immediately are advised to use a firewall to protect vulnerable systems and restrict management access to trusted IP addresses.
The company has also published indicators of compromise to help organizations identify possible attacks.
In recent months, several other Check Point vulnerabilities came under exploitation, including CVE-2026-85102, an improper certificate validation flaw that can lead to remote code execution, as well as CVE-2026-50751 and CVE-2026-16232 - two authentication bypass vulnerabilities that were exploited in ransomware attacks.