VORANT. Threat Intelligence Sign in Get the full feed

Check Point Security Management RCE exploited

high vulnerability

CERT-FR warns of actively exploited RCE flaw CVE-2026-93616 in Check Point Security Management Server, requiring the R82.20 patch.

CERT-FR has issued an advisory regarding a vulnerability in Check Point's Security Management Server and Multi-Domain Security Management Server that allows remote code execution and data integrity compromise. The vendor confirms the flaw, tracked as CVE-2026-93616, is being actively exploited in the wild.

Affected systems are those running Security Management Server or Multi-Domain Security Management Server without the R82.20 patch. Check Point recommends restricting access to the administration interface and not exposing it to the Internet as an interim mitigation. Indicators of compromise are available in the vendor's advisory (sk1000171, published 22 September 2026).

Defenders operating Check Point Security Management infrastructure should apply the R82.20 patch immediately, audit exposure of the admin interface to the internet, and review the vendor-provided IOCs for signs of compromise given confirmed active exploitation.

Mentioned in this report

Vulnerabilities CVE-2026-93616KEV

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1219

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free