The Control Tower Left Unguarded: Check Point’s Management Server Zero-Day Gave Attackers Two Months of Silent Access
grep -nHP “login\(loginRequest=LoginRequest\{authenticationInfo=AuthenticationInfoBase\{username='[^’]{1001,}'” “$MDS_FWDIR”/log/cpm.elg* That command, published in Check Point’s advisory sk1000171, is the first thing an administrator should run on every Security Management Server this week. It searches for oversized login usernames in the management service logs — an artifact left behind by the exploitation of CVE-2026-93616, a pre-authentication path traversal that allows unauthenticated…