Check Point has warned customers that attackers are exploiting a critical zero-day vulnerability in its Security Management infrastructure. Tracked as CVE-2026-93616, the flaw carries a CVSS score of 9.8 and enables an unauthenticated remote attacker to upload and execute arbitrary scripts on an exposed Management Server. Check Point says it has identified a handful of targeted customer attacks and has released emergency fixes. The vulnerability combines directory traversal with unsafe file-upload behavior in the Check Point Management web service. By manipulating file paths, an attacker can cause the service to execute a script from an arbitrary location and load an arbitrary Java class without first authenticating. Successful...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!