Cyber Resilience
← All news
Confirmed

Check Point security advisory (AV26-933)

Our takeCheck Point confirms a critical zero-day in its Management Servers (CVE-2026-93616) that has been exploited in the wild since July. Patch R81.20, R82 and R82.10 to the latest Jumbo Hotfix immediately.
Sources (3)
What this means for you — Security leader:Check Point released emergency patches for CVE-2026-93616 (exploited since July) in Security Management Server, Multi-Domain Security Management, Log Server and Multi-Domain Log Server on R81.20, R82 and R82.10. Apply the fixes on an emergency change path and review management-server logs for indicators of compromise.
What this means for you — Lean IT orgs:If you run Check Point Security Management Server, Multi-Domain Management or Log Servers on R81.20, R82 or R82.10, install the emergency update immediately. Contact your Check Point partner or MSP today to get it applied and check for signs of compromise.
What this means for you — MSP:Check Point CVE-2026-93616 has been exploited in the wild since July 2026 on Security Management, Multi-Domain Management, Log Server and Multi-Domain Log Server (R81.20/R82/R82.10). Patch all affected customer instances on emergency priority and scan management-server logs for post-exploitation activity.
What this means for you — Researcher:Check Point published AV26-933 for CVE-2026-93616, a pre-auth RCE in its management-server products that has been exploited since at least 23 July 2026. Review the advisory and associated IOCs for detection and forensic work.