• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-93616: pre-auth directory traversal in Check Point Quantum Security Management

An unauthenticated attacker can upload and run arbitrary scripts on Check Point Quantum Security Management servers, enabling remote code execution (CVE-2026-93616). The issue affects multiple R80, R81 and R82 branches (including R82.20 without a Jumbo Hotfix, R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, and several R80/R81 releases listed as EOS). Exploitation requires network access to the management or log server; no valid account or user interaction is required.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.19654
CWE
CWE-22
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog with a short remediation deadline, and public exploit code is available, so owners should act immediately to reduce internet exposure and apply vendor guidance.

What is CVE-2026-93616?

An unauthenticated attacker can upload and run arbitrary scripts on Check Point Quantum Security Management servers, enabling remote code execution (CVE-2026-93616). The issue affects multiple R80, R81 and R82 branches (including R82.20 without a Jumbo Hotfix, R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, and several R80/R81 releases listed as EOS). Exploitation requires network access to the management or log server; no valid account or user interaction is required. The weakness is classified as CWE-22 (Path Traversal).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Check Point Quantum Security Management are affected?

BRANCHAFFECTEDFIXED
Quantum Security ManagementR82.20 with no Jumbo Hotfix
Quantum Security ManagementR82.10 with Jumbo Hotfix Take 44 or below
Quantum Security ManagementR82 with Jumbo Hotfix Take 126 or below
Quantum Security ManagementR81.20 with Jumbo Hotfix Take 166 or below
Quantum Security ManagementR81.10 (EOS) with Jumbo Hotfix Take 190 or below
Quantum Security ManagementR81 (EOS)
Quantum Security ManagementR80.40 (EOS)
Quantum Security ManagementR80.30 (EOS)
Quantum Security ManagementR80.20 (EOS)
Quantum Security ManagementR80.10 (EOS)

Is CVE-2026-93616 being exploited?

CISA added CVE-2026-93616 to the Known Exploited Vulnerabilities catalog on 2026-09-22, and U.S. federal agencies were directed to address it by 2026-09-25. Public exploit code is available.

How to fix CVE-2026-93616

  1. Immediately block or restrict network access to Quantum Security Management and associated log servers from untrusted networks.
  2. Follow Check Point’s mitigation guidance and apply any recommended configuration changes or workarounds.
  3. Monitor management and log servers for unexpected file uploads, script execution, and related indicators of compromise.
  4. If vendor mitigations are unavailable for cloud deployments, follow CISA BOD 26-04 guidance and consider discontinuing or isolating the service until resolved.

Frequently asked questions

Is CVE-2026-93616 being actively exploited?

CISA added CVE-2026-93616 to the Known Exploited Vulnerabilities catalog on 2026-09-22 and required remediation by 2026-09-25; public exploit code is also available.

Which Quantum Security Management versions are affected by CVE-2026-93616?

Multiple Check Point Quantum Security Management releases are affected, including R82.20 without a Jumbo Hotfix; R82.10 with Jumbo Hotfix Take 44 or below; R82 with Jumbo Hotfix Take 126 or below; R81.20 with Jumbo Hotfix Take 166 or below; R81.10 (EOS) with Jumbo Hotfix Take 190 or below; and several R80/R81 releases listed as end-of-support.

Is there a patch for CVE-2026-93616?

No vendor patch is listed as available for CVE-2026-93616; Check Point guidance and mitigations should be applied until a fixed release is published.

Does CVE-2026-93616 require authentication?

No, the vulnerability allows unauthenticated attackers to upload and execute scripts on affected Quantum Security Management servers.

References