← Back to search

CVE-2026-93616

9.8 CRITICAL

Published 2026-09-22 · Updated 2026-09-23

AI risk analysis

Summary
A directory traversal and file upload vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts on the Check Point Management Server, potentially leading to remote code execution.
Exploitability
Exploitation is relatively straightforward as it requires no authentication and can be performed by unprivileged attackers.
Blast radius
If exploited, this vulnerability could lead to complete compromise of the Check Point Management Server, including unauthorized execution of scripts and potential data exfiltration.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the version 12.8.100 or later.
rcefile-uploadunauthweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-22

Vendors

checkpoint

Products

multi-domain security management, quantum security management

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.