Planet Briefing

First published · Last updated

CVE-2026-93616: Check Point Multiple Products Path Traversal Vulnerability

CISA reports a path traversal vulnerability in Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent that allows an unauthenticated attacker to upload and execute arbitrary scripts. CISA requires applying vendor mitigations and following BOD 26-04 and forensics triage guidance or discontinuing the product if mitigations are unavailable.

Categories: technology

Generated scores

Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.

Confidence
6/10
Geographic reach
5/10
Global importance
5/10
Impact magnitude
5/10
Positivity
2/10
Urgency
7/10

Why it matters

Exploitation allows an unauthenticated attacker to upload and execute arbitrary scripts on affected products, prompting required mitigations.

Location

Sources

Report an issue