{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-93616",
  "revision": 1,
  "title": "Check Point Management Server — pre-auth path traversal to RCE",
  "summary": "A path traversal in Check Point management and log servers lets an unauthenticated attacker upload an executable script outside the intended directory and run it, taking over the console that manages the gateway estate.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-09-22",
    "prerequisites": "Network access to the management server's web service; no account and no user interaction needed."
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Patch Security Management, Multi-Domain and Log servers per Check Point sk1000171 now; hunt for unexpected scripts and jobs on the management host.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-93616",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-93616",
      "retrieved_at": "2026-09-23T07:33:20.707Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93616",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    }
  ],
  "published_at": "2026-09-22T13:17:11.963Z",
  "issued_at": "2026-09-23T07:33:20.707Z",
  "tags": [
    "check-point",
    "management-server",
    "path-traversal",
    "remote-code-execution",
    "kev"
  ]
}
