Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5525 articles · 220882 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-93616KEVEXPLOITED
checkpoint · quantum security management

Directory Traversal and File upload allows execution of arbitrary script on the Management Server

Description

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

Affected Products

VendorProductVersions
checkpointquantum security managementR82.20 with no Jumbo Hotfix, R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, R81.10 (EOS) with Jumbo Hotfix Take 190 or below, R81 (EOS), R80.40 (EOS), R80.30 (EOS), R80.20 (EOS), R80.10 (EOS), R80 (EOS)

References

  • https://support.checkpoint.com/results/sk/sk1000171

Related News (1 articles)

Tier C
VulDB4h ago
CVE-2026-93616 | Check Point Quantum Security Management up to R81 (EOS) path traversal
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-22
PublishedSep 22, 2026
Trending Score113🔥
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-91843
Stack overflow in login process to the Security Management and Log Servers
Trending: 66
NONECVE-2026-16232EXP
Authentication Bypass in the SmartConsole Login Process Using an Application Token
Trending: 54
CRITICALCVE-2026-85103
Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
Trending: 49
CRITICALCVE-2026-62144
Management Authentication Bypass and Privilege Escalation
Trending: 39
NONECVE-2026-18574
Authentication Bypass in Check Point Security Management Server
Trending: 35

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 22, 2026
Added to CISA KEV
Sep 22, 2026
Discovered by ZDM
Sep 22, 2026
Actively Exploited
Sep 22, 2026