Jessica Entwistle
September 23 2026
Check Point has released patches for a critical zero-day vulnerability in its Security Management Server that was exploited in targeted attacks on 23 July 2026. The flaw, tracked as CVE-2026-93616, allows an unauthenticated attacker with access to the server's web service to execute arbitrary scripts without logging in. SecurityWeek reports that Check Point released the fix on 22 September 2026, more than two months after the vulnerability was exploited in the wild. The Security Management Server is a central component in Check Point's architecture, used to manage firewall policies and security configurations across an organisation's network infrastructure. The delay between exploitation and patch availability highlights the risk window that organisations face when zero-day vulnerabilities are discovered in widely deployed management platforms.
For UK organisations using Check Point infrastructure, this incident underscores the importance of rapid patch deployment for management and control plane systems. Management servers sit at the centre of security policy enforcement, and a compromise at this level can undermine the effectiveness of perimeter and network security controls across the entire estate. The fact that this vulnerability was exploited in targeted attacks before a patch was available means that organisations using Check Point should review access logs, authentication records, and configuration changes on their management servers for signs of unauthorised activity during the period between July and September. This is also a reminder that management interfaces should be isolated from general network access, protected by additional authentication layers, and monitored closely for unusual activity. The two-month window between exploitation and patch availability illustrates the operational risk created when critical infrastructure components are targeted by sophisticated attackers.
Organisations using Check Point Security Management Servers should confirm that CVE-2026-93616 has been patched and review access logs, authentication records, and configuration changes for the period between July and September 2026 to identify any signs of unauthorised activity. Security teams should also review whether management interfaces are appropriately isolated from general network access, whether additional authentication controls such as multi-factor authentication are in place, and whether monitoring is configured to detect unusual authentication attempts or configuration changes. This is also a prompt to review patch management processes for critical infrastructure components and ensure that management plane security is treated as a priority area with clear ownership and regular review.
Source: SecurityWeek