CISA Warns of Multiple Check Point Product Vulnerabilities Exploited in Attacks
CISA says two Check Point flaws, including unauthenticated remote code execution, are being exploited.
CISA added two actively exploited Check Point vulnerabilities to the Known Exploited Vulnerabilities catalog on September 22, 2026, with a September 25 remediation deadline. CVE-2026-85102 is an improper certificate validation flaw in Security Gateway and Spark Firewall Site-to-Site or Remote Access VPN that lets an unauthenticated attacker execute arbitrary code. CVE-2026-93616 is a path traversal bug in management and logging products, including Security Management Server and SmartEvent, that allows unauthenticated upload and execution of arbitrary scripts. CISA says ransomware use is unknown and urges patching, exposure checks, and forensic review.