CVE-2026-93616: Check Point Security Management Server Path Traversal Zero-Day in CISA KEV
Check Point has issued an urgent security notice detailing CVE-2026-93616, a critical zero-day vulnerability in the web service of Check Point Security Management Server. Discovered during targeted intrusions against enterprise security operations centers, the flaw enables unauthenticated remote attackers to perform directory traversal, upload arbitrary scripts, and compromise central firewall orchestration planes.
Technical Mechanics: Web Service Traversal on Port 19009
Check Point Security Management Servers run a proprietary management web daemon listening on TCP port 19009 to handle SmartConsole telemetry and automated provisioning workflows. The daemon’s endpoint for processing client-side diagnostic bundles fails to sanitize relative directory sequences (../) embedded in multi-part HTTP parameters.
Attacker (Internet / Adjacent Subnet) -> TCP Port 19009
└── HTTP POST /CPM/Service/UploadDiagnostic
├── Param: filename="../../../../../opt/CPsuite-R81.20/fw1/scripts/backdoor.sh"
├── File written to executable directory on Management Server OS
└── HTTP GET /CPM/Service/Execute -> Trigger backdoor.sh -> Root OS Access
Because the Security Management Server holds administrator credentials, private encryption keys, and security policy definitions for all managed security gateways across an enterprise, compromising this single node gives attackers the ability to disable firewall inspection and inject rogue rule definitions across the entire network fabric.
Remediation Checklist
- Apply Jumbo Hotfix Accumulator: Install the R82.20 security hotfix or the latest Jumbo Hotfix Accumulator applicable to your deployed Gaia OS version.
- Block Port 19009 at Perimeter: Enforce strict perimeter firewall rules ensuring TCP port 19009 is never reachable from external or non-admin subnets.
- Audit SmartConsole Administrator Accounts: Inspect management logs for unauthorized administrator creation or unexpected policy installations.