Check Point CVE-2026-93616: Management Server Patch Checklist
September 23, 2026
Update September 23, 2026: CISA added CVE-2026-93616 to its Known Exploited Vulnerabilities catalog on September 22. Check Point says the flaw affects several on-premises security-management and logging products and can let an unauthenticated attacker execute a script. Administrators should identify affected management servers, limit their exposure, and install the vendor’s applicable hotfix or Jumbo Hotfix Accumulator promptly.
Which Check Point systems need attention?
Check Point lists Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent as affected products. The advisory lists R82.20, R82.10 Jumbo Hotfix Take 44 or lower, R82 Jumbo Hotfix Take 126 or lower, R81.20 Jumbo Hotfix Take 166 or lower, and R81.10 Jumbo Hotfix Take 190 or lower, along with older end-of-support releases. Check your exact product and build against the live advisory; a release family name alone is not enough to establish that an installation is patched.
The vendor says Smart-1 Cloud has already been patched and identifies Check Point Firewall Appliances and Check Point Spark Firewall as not affected by this particular management-server issue. Do not confuse CVE-2026-93616 with the separately tracked Check Point gateway issue CVE-2026-85102.
What should administrators do?
- Inventory the management and logging servers, their owners, installed builds, and administrative-network exposure. Prioritize systems reachable outside trusted management networks.
- Restrict management access to authorized networks while scheduling the supported fix. Preserve legitimate administrator, logging, monitoring, and recovery access.
- Use Check Point’s R82.20 Security Hotfix where applicable. The vendor also lists the fix in Jumbo Hotfix Accumulator R82.10 Take 45 or later, R82 Take 127 or later, R81.20 Take 170 or later, and R81.10 Take 192 or later. Confirm the supported path for each server with the vendor, especially on an end-of-support train.
- Plan maintenance with the product owner, including configuration recovery, service dependencies, and a post-update verification window. Do not assume a LivePatch addresses this issue; the advisory says one is not available.
- If compromise is suspected, preserve relevant logs and configuration evidence under the incident-response process before remediation. Review unexpected administrative changes and affected services without exposing logs or customer information publicly.
- After patching, confirm the installed hotfix level, normal administrator access, policy-management functions, logging, and alert delivery.
For other confirmed patch priorities, see the Fix I.T. Phill security updates archive.
Sources: Check Point advisory sk1000171 and the CISA Known Exploited Vulnerabilities catalog. This is protective guidance based on those sources; Fix I.T. Phill has not independently confirmed exploitation in a customer environment.

