CVE-2026-93616
Check Point Management Server directory traversal + file upload -> unauthenticated arbitrary script execution
- Severity
- critical
- Affected product
- Check Point Security Gateway
- Affected versions
- Check Point Security Gateway all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 2% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-09-23
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Check Point Security Gateway appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-23 (/daily-cve), CVSS 9.8, CISA KEV. Deliberately NOT version-gated: the Check Point appliances.json row carries no `version` regex because the gateway publishes no version anonymously (see that row's own note), so a `lt` here would be permanently dead data - version_in_range refuses an unknown version, and the row would never fire. It rides the advisory arm instead, which names the product's KEV ids on any fingerprinted gateway and is the honest claim strength for a bug we cannot number. The traversal itself is on the MANAGEMENT server, not the gateway's public VPN portal, so there is also no anonymous request that proves it from outside.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →