Check Point Security Management Server zero-day exploited in targeted attacks
Check Point CVE-2026-93616 is being exploited through path traversal leading to arbitrary script execution and Java class loading on management infrastructure. Recent reporting provides affected-version, fixed-hotfix, port-19009 restriction, and July 23 hunting-window context; patch urgently, preserve telemetry, and hunt for unauthorized scripts, web shells, anomalous certificates, and suspicious Java activity.
Sources (2)
Updated Sep 25, 2026