← All CVEs NewScan detects
criticalKEV

CVE-2026-93616

Check Point Management Server directory traversal + file upload -> unauthenticated arbitrary script execution

Severity
critical
Affected product
Check Point Security Gateway
Affected versions
Check Point Security Gateway all versions before the fix
CISA KEV
Listed as a known exploited vulnerability
EPSS
2% chance of exploitation in the next 30 days
Added to NewScan
2026-09-23
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Check Point Security Gateway appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-23 (/daily-cve), CVSS 9.8, CISA KEV. Deliberately NOT version-gated: the Check Point appliances.json row carries no `version` regex because the gateway publishes no version anonymously (see that row's own note), so a `lt` here would be permanently dead data - version_in_range refuses an unknown version, and the row would never fire. It rides the advisory arm instead, which names the product's KEV ids on any fingerprinted gateway and is the honest claim strength for a bug we cannot number. The traversal itself is on the MANAGEMENT server, not the gateway's public VPN portal, so there is also no anonymous request that proves it from outside.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →