AllCyberNews

CVE-2026-93616

Directory Traversal and File upload allows execution of arbitrary script on the Management Server

CVSS 9.8 critical · checkpoint Quantum Security Management · published 2026-09-22

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

Coverage 2 sources

  1. 2026-09-22 CISA Cybersecurity Advisories high CISA Adds Four Known Exploited Vulnerabilities to Catalog

    CISA added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog, indicating active exploitation.

  2. 2026-09-23 Help Net Security critical Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances

    Check Point releases emergency fixes for critical Management Server vulnerability exploited since July 23, 2026.

Mentioned with

CVE-2026-85102 CVE-2026-93952 CVE-2026-94127

Also covered