CISA Adds Multiple Check Point Product Flaws to Exploited Vulnerabilities List
CISA added two actively exploited Check Point flaws, including unauthenticated VPN code execution, to KEV.
CISA added CVE-2026-85102 and CVE-2026-93616 to the KEV catalog on September 22, 2026, warning both are actively exploited, with a federal deadline of September 25 under BOD 26-04. CVE-2026-85102, CVSS 9.8, is improper certificate validation in Check Point Quantum Security Gateway and Spark Firewall VPN configurations, allowing an unauthenticated attacker to execute arbitrary code during VPN negotiation. CVE-2026-93616 is a path traversal in Security Management Server, Multi-Domain Security Management, log servers, and SmartEvent that allows unauthenticated upload and execution of arbitrary scripts. Both entries require forensic triage. CISA has not linked either flaw to ransomware.
- Both Check Point flaws are in CISA's KEV catalog and actively exploited.
- CVE-2026-85102 is CVSS 9.8 unauthenticated VPN remote code execution.
- CVE-2026-93616 lets attackers upload and run scripts on management servers.
- Federal civilian agencies face a September 25, 2026 remediation deadline.
- CISA requires forensic triage; ransomware use is not identified.
Vulnerabilities mentionedAll →
- CVE-2026-851029.8<1%Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flawpublished · Check Point Quantum Security Gateway (VPN negotiation functionality) KEV
Full article542 words · extracted from gbhackers.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities affecting multiple Check Point products to its Known Exploited Vulnerabilities (KEV) catalog.
CISA warns that these flaws are being actively exploited in the wild. Federal civilian agencies must address these vulnerabilities by September 25, 2026, under Binding Operational Directive (BOD) 26-04.
The new vulnerabilities, tracked as CVE-2026-85102 and CVE-2026-93616, impact Check Point security gateways and centralized security management products.
Both issues can allow unauthenticated attackers to gain high-impact access, making internet-facing deployments a priority for immediate investigation and remediation.
VPN Certificate Validation Flaw
CVE-2026-85102 is a critical vulnerability related to improper certificate validation in Check Point Quantum Security Gateway and Check Point Spark Firewall products configured for Site-to-Site VPN or Remote Access VPN connections.
This flaw has a CVSS v3.1 score of 9.8 out of 10, highlighting its network-exploitable nature, low attack complexity, and lack of authentication or user interaction requirements.
This issue is classified as CWE-295, or Improper Certificate Validation. According to the vulnerability description, an unauthenticated remote attacker could exploit the weakness during VPN negotiation to execute arbitrary code on an affected gateway.
Since security gateways often sit at the edge of enterprise networks, successful exploitation could provide an attacker a foothold in a highly sensitive location.
Organizations using affected VPN configurations should identify exposed appliances, review vendor guidance, and apply available mitigations immediately.
Management Server Path Traversal Risk
The second entry, CVE-2026-93616, is a path traversal vulnerability affecting Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. CISA reported that this vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts.
This issue is tracked under CWE-22, where path traversal weaknesses occur when an application does not properly restrict access to file-system paths.
In this case, the impact goes beyond unauthorized file access: an attacker may be able to place and run malicious scripts on vulnerable management infrastructure.
Security management platforms can hold policy configurations, logging data, administrative controls, and connections to multiple protected gateways. Therefore, compromising a management server may grant attackers broader network visibility or control.
CISA added both vulnerabilities to the KEV catalog on September 22, 2026, establishing a remediation deadline of September 25, 2026. The agency has marked both vulnerabilities as requiring forensic triage under BOD 26-04, indicating that affected organizations should not view patching as the only necessary response.
While CISA has not identified either vulnerability as used in ransomware campaigns, this does not reduce the urgency of remediation, especially since both flaws allow unauthenticated remote exploitation and arbitrary code or script execution.
Organizations should prioritize the following actions:
- Inventory Check Point gateways, VPN deployments, management servers, log servers, and SmartEvent systems.
- Determine whether affected systems are internet-facing or reachable from untrusted networks.
- Apply Check Point’s vendor-provided mitigations and updates.
- Perform forensic triage for evidence of suspicious access, unauthorized scripts, configuration changes, or anomalous VPN activity.
- Isolate or discontinue use of vulnerable products where mitigations are unavailable.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.