Check Point warns that a previously unknown vulnerability in its Security Management Server is being exploited in targeted attacks. The company says attackers take advantage of the flaw to run arbitrary scripts on the management server.

The issue is tracked as CVE-2026-93616 and affects the server’s web service. Check Point states that an attacker who can access this web service can execute scripts without logging in. The Hacker News reports the exploitation occurs in a limited number of targeted attacks dated July 23, while also noting Check Point releases a fix on September 22. Bleeping Computer similarly describes the matter as a critical management server weakness and says Check Point provides emergency hotfixes to mitigate the risk.

Across sources, the main differences are the emphasis on timing and the broader framing of the incident. However, both accounts agree on the core technical impact, the CVE identification, and that the company responds with an emergency patch after detecting exploitation.