Executive brief
Check Point's security and logging management products contain a path traversal flaw that allows unauthenticated attackers to upload and run arbitrary code on affected systems. These products are critical infrastructure components used to manage security policies and monitor network activity across enterprises. Exploitation can lead to complete system compromise, unauthorized access to security configurations, and potential lateral movement throughout the network.
Technical details
A path traversal vulnerability in Check Point's Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent allows unauthenticated attackers to bypass upload restrictions and place malicious scripts outside their intended directories. The vulnerability can be exploited over the network without requiring authentication, and attackers can achieve arbitrary code execution by uploading specially crafted scripts that traverse directory boundaries. Active exploitation in the wild indicates this is a high-impact issue requiring immediate patching. The exact vulnerable component and remediation details should be obtained from Check Point's official security advisories.
Affected products
- Check Point Security Management Server
- Check Point Multi-Domain Security Management Server
- Check Point Log Server
- Check Point Multi-Domain Log Server
- Check Point SmartEvent
Timeline
- 2026-09-22: disclosed
- 2026-09-22: exploited