{"id":"CVE-2026-93616","published":"2026-09-22T13:17:11.963","lastModified":"2026-09-23T16:38:38.987","description":"A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-22"],"vendors":["checkpoint"],"products":["multi-domain security management","quantum security management"],"references":[{"url":"https://support.checkpoint.com/results/sk/sk1000171","tags":["Mitigation","Patch","Vendor Advisory"]},{"url":"https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93616","tags":["US Government Resource"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"A directory traversal and file upload vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts on the Check Point Management Server, potentially leading to remote code execution.","exploitability":"Exploitation is relatively straightforward as it requires no authentication and can be performed by unprivileged attackers.","blast_radius":"If exploited, this vulnerability could lead to complete compromise of the Check Point Management Server, including unauthorized execution of scripts and potential data exfiltration.","remediation":"Upgrade to the version 12.8.100 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","file-upload","unauth","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:49:11.809Z"}}