CISA Warns of Multiple Check Point Product Vulnerabilities Exploited in Attacks
CISA says two Check Point flaws, including unauthenticated remote code execution, are being exploited.
CISA added two actively exploited Check Point vulnerabilities to the Known Exploited Vulnerabilities catalog on September 22, 2026, with a September 25 remediation deadline. CVE-2026-85102 is an improper certificate validation flaw in Security Gateway and Spark Firewall Site-to-Site or Remote Access VPN that lets an unauthenticated attacker execute arbitrary code. CVE-2026-93616 is a path traversal bug in management and logging products, including Security Management Server and SmartEvent, that allows unauthenticated upload and execution of arbitrary scripts. CISA says ransomware use is unknown and urges patching, exposure checks, and forensic review.
- CVE-2026-85102 allows unauthenticated remote code execution over VPN.
- CVE-2026-93616 lets attackers upload and execute arbitrary scripts.
- CISA added both flaws to the KEV catalog on September 22, 2026.
- The remediation deadline is September 25; ransomware use is unknown.
Vulnerabilities mentionedAll →
- CVE-2026-851029.8<1%Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flawpublished · Check Point Quantum Security Gateway (VPN negotiation functionality) KEV
Full article402 words · extracted from cybersecuritynews.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency has added two Check Point vulnerabilities to its Known Exploited Vulnerabilities Catalog, warning that attackers are actively exploiting the flaws against affected environments.
The issues affect Check Point Security Gateway, Spark Firewall, Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products.
The first flaw, CVE-2026-85102, is an improper certificate validation vulnerability (CWE-295) affecting Check Point Security Gateway and Spark Firewall deployments using Site-to-Site or Remote Access VPN.
An unauthenticated remote attacker could exploit the flaw to execute arbitrary code on a vulnerable gateway. This means an attacker may be able to run commands or deploy malicious payloads without first obtaining valid user credentials, creating a serious risk for organizations that expose affected VPN services to the internet.
The second issue, CVE-2026-93616, is a path traversal vulnerability affecting multiple Check Point management and logging products. It impacts Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
The weakness is categorized as CWE-22, a flaw type that can let attackers access files or directories outside an intended restricted location.
Check Point Product Vulnerabilities Exploited
According to the advisory details, an unauthenticated attacker can abuse the vulnerability to upload and execute arbitrary scripts. Successful exploitation could give an attacker a foothold in a security-management environment, potentially enabling further network discovery, credential theft, policy manipulation, or malware deployment.
CISA added both vulnerabilities to its KEV Catalog on September 22, 2026, with a September 25 remediation deadline, urging organizations to follow Check Point’s mitigations, assess internet exposure, conduct forensic triage, and discontinue affected products if mitigations are unavailable.
Security teams should prioritize identifying vulnerable Check Point appliances and management servers, especially those reachable from the public internet. Administrators should review authentication records, VPN activity, system logs, uploaded files, and unusual script execution for signs of exploitation before and after remediation.
CISA’s advisory does not identify ransomware use for either vulnerability, listing that status as unknown. However, the ability to execute code or scripts without authentication makes both flaws high-priority risks for organizations using affected Check Point products.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.