PT-2026-96718 · Check Point · Multi-Domain Log Server+5

CVE-2026-93616

·

Published

2026-09-20

·

Updated

2026-10-01

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Security Management Server versions R81.10 through R82.20 Multi-Domain Security Management Server versions R81.10 through R82.20 Log Server versions R81.10 through R82.20 Multi-Domain Log Server versions R81.10 through R82.20 SmartEvent versions R81.10 through R82.20
Description A directory traversal and file upload flaw in the Check Point Management web service allows an unauthenticated remote attacker to bypass authentication, upload, and execute arbitrary scripts on the system. Directory traversal is a technique that allows an attacker to access files and directories that are stored outside the web root folder. This issue has been exploited in the wild in targeted attacks against a small number of customers since July. Successful exploitation could allow an attacker to gain access to the management plane and potentially influence the configuration of the protected infrastructure, including firewalls and VPN gateways.
Recommendations For Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent:
  • Update R82.20 to Security Hotfix Take 1.
  • Update R82.10 to Jumbo Hotfix Take 45 or later.
  • Update R82 to Jumbo Hotfix Take 127 or later.
  • Update R81.20 to Jumbo Hotfix Take 170 or later.
  • Update R81.10 to Jumbo Hotfix Take 192 or later.
  • Restrict access to TCP port 19009 so it is reachable only from trusted IP addresses.
  • Place vulnerable systems behind a firewall to limit access to trusted IP addresses via the SmartConsole dashboard.

Exploit

Fix

RCE

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15065
CVE-2026-93616

Affected Products

Check Point Gaia
Klog Server
Multi-Domain Log Server
Multi-Domain Management
Security Management
Smartevent