Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN918
_____________________________________________________________________

DATE                : 23/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):  Systems running Multi-Domain Security Management
                        Server, Security Management Server versions
                        prior to R82.20 Security Hotfix (TAR).
  
=====================================================================
https://support.checkpoint.com/results/sk/sk1000171/
_____________________________________________________________________

CVE-2026-93616: Directory Traversal and File upload allows execution
of arbitrary script on the Management Server


Please read this important update from Check Point.

Security Alert:
High

ProductMulti-Domain Security Management Server, Security Management
Server

VersionR81 (EOS), R81 (EOS), R81.10 (EOS), R81.10 (EOS), R81.20,
R81.20, R82, R82, R82.10, R82.10, R82.20, R82.20


Last Modified2026-09-22

Symptoms

        A directory traversal and file upload vulnerability allows
an unauthenticated attacker to upload and execute arbitrary scripts
on the Check Point Management Server.


        This vulnerability is exploited in the Wild. Check Point is
aware of a handful of customers who have been attacked.

        This issue received the ID CVE-2026-93616 and a CVSS score
of 9.8.

        Affected Products: Security Management Server, Multi-Domain
Security Management Server, Log Server, Multi-Domain Log Server,
SmartEvent.

        Not Affected Products: Smart-1 Cloud (fix is already applied),
Check Point Firewall Appliances, Check Point Spark Firewall.


        Affected Versions: 
            R82.20
            R82.10 Jumbo Hotfix Take 44 or lower
            R82 Jumbo Hotfix Take 126 or lower
            R81.20 Jumbo Hotfix Take 166 or lower
            R81.10 Jumbo Hotfix Take 190 or lower (EoS)
            R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)
        Note: Check Point LivePatch Take 28/29 does not address this
issue.


    Mitigation

    Limit access to your Management Servers behind a Security
Gateway/Check Point Firewall according to the Check Point Gateway
and Management Hardening Administration Guide.

        Make sure that access to port TCP/19009 is only possible
from Trusted IP addresses.
        If you already have a Security Gateway / Check Point
Firewall with implied rules enabled, make sure your Trusted
Clients are limited to trusted internal IP addresses. This will
create an Implied rule limiting access.

        To do so:
            In SmartConsole, go to
Manage & Settings > Permissions & Administrators > Trusted Clients.
            Double-click the client you want to edit.
            In the Trusted Client configuration window that
opens, change the settings as needed.
            Click OK.


    Indication of Compromise

    Check for these two indicators of compromise on every Security
Management, Multi-Domain Security Management, Log, Multi-Domain
Log, and SmartEvent Server:

        Run this command from Expert mode:

        grep -nHP "login\(loginRequest=LoginRequest\{authenticationInfo=AuthenticationInfoBase\{username='[^' ]{1001,}'" "$MDS_FWDIR"/log/cpm.elg*

        Output Example:

        /opt/CPsuite-R82/fw1/log/cpm.elg.13:653:17/09/26 17:30:03,562 INFO coresvc.internal.LoginSvcImpl [qtp1491953039-6857]: login(loginRequest=LoginRequest{authenticationInfo=AuthenticationInfoBase{username='abcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdababcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcdabcd'}, connectionMode=READ_WRITE, applicationName='SmartConsole', userAgent='null', actionOnOtherClientSession=NO_ACTION, workSessionId='null', workSessionMode=USE_EXISTING, workSessionType=PRIVATE, keepAliveTimeout=0, getDomainList=true, domain=null, domainName='null', domainIp='10.x.x.x', remoteIpAddr='null', VersionDetails=VersionDetails{majorVersion='R82', minorVersion='R82', officialName='R82', smartConsoleBuild='null'}})

        If the above command returns an output, check if there is an
FWM/MDS core dump file that was generated at the same time. Run: 

        ls -l /var/log/dump/usermode/ | grep -e fwm -e mds

        If a core dump file was generated at the same time as the
login attempt returned by the first command, there has been a
potential attempt to exploit this vulnerability in your environment.

        Run this command from Expert mode:
        grep -E "ERROR.*upgrade\.base\.ReflectionUtils.*Failed to
load allResourceFiles map from" $MDS_FWDIR/log/cpm.elg*

        If this command returns an output, this means that there
has been a potential attempt to exploit this CVE in your
environment.

        Review the output for suspicious file paths containing
directory traversal sequences (for example, ../).

        Output Example:
        18/09/26 21:54:57,396 ERROR upgrade.base.ReflectionUtils [qtp700085606-66\]: Failed to load allResourceFiles map from /opt/CPupgrade-tools-../../../../tmp/003193_VULNCHECK/scripts/upgrade_files.conf

        In this example, the path contains a directory traversal
sequence (../../../../), which may indicate an attempt to exploit
the vulnerability.


Solution

This problem was fixed. 

    Download the R82.20 Security Hotfix (TAR)

The fix is also included in:

    Jumbo Hotfix Accumulator for R82.10 starting from Take 45
    Jumbo Hotfix Accumulator for R82 starting from Take 127
    Jumbo Hotfix Accumulator for R81.20 starting from Take 170
    Jumbo Hotfix Accumulator for R81.10 starting from Take 192

Notes:

    These Jumbo Hotfix Accumulators also include the fix for
CVE-2026-91843 (sk1000155).
    Because of the nature of the fix, a LivePatch is not be
available for this issue.


Article Properties
Access Level          General
Severity              HIGH
Status                Approved
Date Created          2026-09-20
Last Modified         2026-09-22


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




