# Check Point patches management-server zero-day used in targeted attacks

_Published Tuesday, September 22, 2026 at 8:08 PM EDT · Security, Infrastructure · Latest · Tier 1 — Major_

![Check Point patches management-server zero-day used in targeted attacks — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipTjrp93lIMdPVKigtkoXjbsk75AIXEvqJuXoYMQLAmvzQfqSy3V1XhBTLXY1SAWp92vTbajtnxBgHYvDr2e3EZOi9Yf8KgT8EzQOp61PjmPsI55nERsYckaL-pfmQDDzRTiCWXegVWrJ0Fu_9I8GUi5O0M0103r218S3dC67Zmr9BZ3quLBRBm9T6Xqo/s1700-nu-rw-lo-l85-e365/cp-upload.jpg)

Check Point released a September 22 fix for CVE-2026-93616, a Security Management Server flaw that attackers exploited in a handful of targeted attacks on July 23. The path-traversal vulnerability lets an unauthenticated attacker with access to the server's web service upload and execute scripts; Check Point rated it 9.8 out of 10.

Administrators must install the specific fix and inspect systems using Check Point's hunting guidance because patching does not reveal earlier compromise. The company did not identify the targets, attackers or actions taken after exploitation.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/check-point-warns-of-management-server.html)

---
Canonical: https://techandbusiness.org/newswire/11nDp_6rMqVCuHQVF_brAp
Published: 2026-09-23T00:08:24.060Z
Story chronology: 2026-09-22T18:29:39.000Z
Retrieved: 2026-09-23T01:26:10.170Z
Publisher: Tech & Business (techandbusiness.org)
