Arbitrary file upload in Gaia - CVE-2026-93616
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file names during file upload on the Check Point Management Server. A remote non-authenticated attacker can upload a malicious file and execute it on the server.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2026-93616
Install updates from vendor's website.
For the R82.20 release the vendor has issued a hotfix:
https://support.checkpoint.com/results/download/145601