Directory Traversal and File Upload Vulnerability in Check Point Management Server
CVE-2026-93616

9.8CRITICAL

Key Information:

Vendor

Checkpoint

Vendor
CVE Published:
22 September 2026

What is CVE-2026-93616?

A directory traversal vulnerability, combined with a file upload flaw, allows attackers without authentication to upload and execute arbitrary scripts on the Check Point Management Server. This dangerous combination can lead to unauthorized access and potential server exploitation. It poses a significant risk to the integrity and security of the affected systems, requiring immediate attention and remediation efforts.

Affected Version(s)

Quantum Security Management R82.20 with no Jumbo Hotfix

Quantum Security Management R82.10 with Jumbo Hotfix Take 44 or below

Quantum Security Management R82 with Jumbo Hotfix Take 126 or below

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.