One Port to Root: Weaponizing Check Point Management CVE-2026-93616

Bishop Fox details CVE-2026-93616, a 9.8-severity flaw in Check Point Security Management and Multi-Domain Management servers that is already being exploited in real attacks. An unauthenticated attacker who can reach the server over TCP port 19009 can write files as root and escalate that into full remote code execution. The researchers reproduced the attack end to end against unpatched R81.10 and R82.10 lab servers.

Source: bishopfox.com

Curated Permalink