What's new: Reports from CSO Online, Qualys, GBHackers, and Cyber Security News largely corroborate the established picture and add specifics: both flaws are confirmed CVSS 9.8; the affected-build list for the management flaw is extended to R82.20 and R82.10 Take 44 and below (The Hacker News); additional IOC certificate subjects CN=vpn-user and CN=vpnuser are reported; new guidance calls for hunting cpm.elg…
Merged summary · glm-5.3 · rewritten as coverage arrives
Check Point confirmed active exploitation of two CVSS 9.8 pre-authentication flaws — CVE-2026-93616 (Management Server path traversal/file upload, zero-day since July 23) and CVE-2026-85102 (VPN certificate-validation RCE) — both added to CISA's KEV catalog…
Check Point is responding to two actively exploited, CVSS 9.8 pre-authentication vulnerabilities. CVE-2026-93616 is a directory-traversal and unsafe-file-upload flaw in the Security Management Server web service that lets an unauthenticated remote attacker upload and execute arbitrary scripts and load an arbitrary Java class. It affects Security Management, Multi-Domain Security Management, Log Server, and SmartEvent — with affected builds including R82.20, R82.10 Take 44 and below, and older R81/R80 releases — while Smart-1 Cloud, firewall appliances, and Spark are unaffected. Check Point observed targeted attacks against a handful of customers on July 23, 2026 and shipped a fix on September 22, 2026 via the R82.20 hotfix and Jumbo Hotfix Accumulator takes for R82.10, R82, R81.20, and R81.10. LivePatch does not remediate it (including Takes 28 and 29 and the September 16 LivePatch for CVE-2026-91843); Check Point advises restricting TCP port 19009 to trusted addresses and hunting cpm.elg logs and core dumps for traversal indicators. In parallel, CVE-2026-85102 is an improper certificate-validation flaw in Site-to-Site and Remote Access VPN on Quantum Security Gateway and Spark Firewall that allows unauthenticated arbitrary code execution during VPN negotiation, triggered by a malicious certificate (Qualys also characterizes it as an authentication bypass). It was patched on September 9, 2026, and exploitation attempts against Spark customers began September 12, 2026 — three days later — from VPN and proxy infrastructure using certificates with subjects such as CN=vpn, CN=vpn-user, CN=vpnuser, and OU=users, O=global; The Hacker News reports that successful exploitation is unconfirmed. Fixes for the VPN flaw include LivePatch Take 26 and specified Jumbo Hotfix takes. CISA added both CVEs to the Known Exploited Vulnerabilities catalog on September 22, 2026 under BOD 26-04, giving federal civilian agencies until September 25, 2026 to remediate, with forensic triage and exposure checks required; ransomware use has not been identified. Check Point urges immediate patching plus hunts for anomalous certificate logins and internal scans, and Qualys QIDs 388806 and 388699 detect vulnerable assets. Sources disagree on two points: Qualys says R82.20 fixes the VPN bug while Cyber Security News says R82.20 is unaffected by it, and Help Net Security says the same KEV action covered four zero-days — also adding Arista VeloCloud Orchestrator CVE-2026-93952 and F5 BIG-IP…
CVE-2026-93616: CVSS 9.8 pre-authentication directory traversal and file upload in the Security Management Server web service, enabling arbitrary script execution and arbitrary Java class loading.
Affected management products: Security Management, Multi-Domain Security Management, Log Server, and SmartEvent; affected builds include R82.20, R82.10 Take 44 and below, and older releases; Smart-1 Cloud, firewall appliances, and Spark…
CVE-2026-93616 was exploited as a zero-day on July 23, 2026 against a handful of customers; the fix shipped September 22, 2026 via the R82.20 hotfix and Jumbo Hotfix Accumulator takes for R82.10, R82, R81.20, and R81.10.
LivePatch — including Takes 28 and 29 and the September 16 LivePatch for CVE-2026-91843 — does not fix CVE-2026-93616; restrict TCP/19009 to trusted addresses and hunt cpm.elg logs and core dumps for traversal indicators.
CVE-2026-85102: CVSS 9.8 improper certificate validation allowing unauthenticated RCE during VPN negotiation on Quantum Security Gateway and Spark Firewall; patched September 9, 2026, with Spark exploitation attempts beginning September…
Observed IOC certificate subjects: CN=vpn, CN=vpn-user, CN=vpnuser, and OU=users, O=global; VPN-flaw fixes include LivePatch Take 26 and listed Jumbo Hotfix takes.
CISA added both CVEs to the KEV catalog on September 22, 2026 under BOD 26-04, with a September 25, 2026 remediation deadline for federal civilian agencies, mandatory forensic triage, and no identified ransomware use.
Qualys QIDs 388806 and 388699 detect vulnerable assets; sources disagree on R82.20's role for the VPN flaw (Qualys: fixes it; Cyber Security News: unaffected).
CISA added four actively exploited Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its KEV catalog, with federal fixes due September 25.
Authentication Bypass in Check Point SmartConsole Grants Full Admin Access
Check Point SmartConsole, the administrative client used to manage Quantum Security Management and Multi-Domain Security Management, contains an authentication bypass (CWE-287) in its login process that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Exploitation is possible when the Management Server IP address is reachable from the internet and the configuration does not restrict Trusted Clients. A successful attacker can modify security policies and security configurations, effectively taking control of firewall management. Any organization running an internet-exposed Check Point management server without Trusted Client restrictions is affected, though Check Point reports exploitation has impacted only a very small number of customers. The flaw was added to CISA's KEV on 2026-07-22, is actively exploited, and press reports indicate public proof-of-concept code has been released.
Do: Apply the fix released in Check Point's advisory for CVE-2026-16232 by updating SmartConsole and the associated Quantum/MDS management software; no fixed version numbers were provided in this data, so confirm them against the vendor bulletin. As an interim mitigation, restrict internet access to the Management Server IP address and configure Trusted Clients so SmartConsole connections are accepted only from known administrator addresses. Review management logs for unexpected logins, unauthenticated token issuance, or unfamiliar administrator sessions, and complete remediation per CISA BOD 26-04 given the KEV listing.
9.3
78%
KEV
Check Point SmartConsole
Check Point Quantum Security Management
Check Point Multi-Domain Security Management
largeplausibly tens of thousands of Check Point management deployments, though the vulnerable subset is only those with an internet-exposed Management Server and no…
Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flaw
CVE-2026-85102 is an improper certificate trust-validation flaw (CWE-295) in the VPN negotiation code of Check Point Quantum Security Gateways. An unauthenticated remote attacker who can reach the gateway's VPN service can trigger the flaw during VPN negotiation, where certificates involved in the exchange are not properly validated, and achieve code execution on the gateway. Successful exploitation yields arbitrary code execution on the gateway with high impact on confidentiality, integrity, and availability (CVSS 9.8), amounting to full compromise of the security gateway. The affected population is organizations running Quantum Security Gateways with VPN services reachable from untrusted networks. As of the available reporting there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation is confirmed; the issue was disclosed alongside a second, similarly rated (9.8) Check Point VPN certificate-validation RCE flaw.
Do: Upgrade Quantum Security Gateways to the fixed versions listed in Check Point's advisory (AV26-902) as soon as they are published, prioritizing internet-facing VPN gateways. Until patched, restrict exposure of VPN negotiation endpoints to trusted networks and monitor VPN services for anomalous handshake activity. Inventory which gateways in your estate expose VPN services publicly and treat those as the highest-priority targets.
9.8
<1%
KEV
Check Point Quantum Security Gateway (VPN negotiation functionality)
Unauthenticated RCE in Check Point Quantum VPN Certificate ASN.1 Decoding
CVE-2026-85103 is a heap-based buffer overflow (CWE-122) in the ASN.1 certificate-decoding code used by Check Point's VPN implementation, rated 9.8 Critical with a network-exploitable, unauthenticated, low-complexity vector. An unauthenticated remote attacker can trigger the flaw by sending crafted certificate data that the VPN service parses during connection handling, causing heap corruption that allows arbitrary code execution on the target system. Successful exploitation grants the attacker code execution with high confidentiality, integrity, and availability impact, which on security gateways and management servers could mean control of the security infrastructure itself. Any organization running Check Point Quantum Security Management or Quantum Security Gateway systems that process VPN certificate traffic is potentially affected, and the advisory set indicates this flaw was disclosed alongside a second, similarly rated 9.8 VPN certificate vulnerability (Check Point advisory AV26-902). There is no evidence of exploitation so far: the flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known.
Do: Patch promptly: because this is an unauthenticated, network-reachable 9.8-rated RCE in the VPN path, upgrade Quantum Security Management and Quantum Security Gateway deployments per Check Point's advisory (referenced as AV26-902), and check your current software versions against the affected/fixed ranges listed there, which are not specified in the data available here. Until patched, restrict access to exposed VPN and management interfaces to trusted source IPs where possible and monitor VPN endpoints for anomalous connection or crash behavior. Inventory all Quantum appliances and management servers, since the flaw affects both product lines and was disclosed together with a second 9.8 VPN certificate flaw.
Unauthenticated stack overflow gives root RCE in Check Point login process
CVE-2026-91843 is a stack-based buffer overflow (CWE-121) in the unauthenticated login process of a Check Point product, as Check Point Software (cve@checkpoint.com) is the assigning CNA and its CVE scope covers Check Point products. An attacker can trigger the flaw remotely by sending crafted input to the login interface before authenticating, with no user interaction or credentials required. Successful exploitation allows arbitrary code execution with root privileges, the highest level of control on the affected system. The vulnerability is rated 9.8 Critical (AV:N/AC:L/PR:N/UI:N, all impacts high), reflecting trivial network exploitability. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time, and the source data does not name the specific product line or affected version ranges.
Do: Monitor Check Point's official advisory channels for the affected product/version list and patch release, and upgrade as soon as fixed versions are published. In the interim, restrict the login/management interface of Check Point appliances to trusted management networks and remove any direct internet exposure, and review perimeter logs for anomalous pre-authentication traffic against that interface.
Unauthenticated RCE in Check Point Management Server via Directory Traversal and File Upload
This vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server, achieving high confidentiality, integrity, and availability through directory traversal and file upload attacks. An attacker can leverage this flaw to compromise sensitive systems and gain extensive control over the management environment. The affected scope includes all Check Point Management Server installations, with no specific version range identified in the provided data.
Do: Upgrade to patched Check Point Management Server versions immediately; disable/block directory traversal and file upload features; audit all management server deployments and verify plugin installation status; monitor for new CVEs and update policies.
Unauthenticated Input-Validation Flaw in VeloCloud Orchestrator (On-Prem)
An improper input validation flaw (CWE-20) in the on-premises VeloCloud Orchestrator (VCO) allows a remote, unauthenticated attacker to reach privileged internal functionality on the orchestrator host. Exploitation occurs over the network with no credentials or user interaction (attack complexity is high), and success compromises the confidentiality, integrity, and availability of the orchestrator and the data it manages; the CVSS 4.0 vector also flags high impact on subsequent systems, meaning the SD-WAN edges and sites the orchestrator controls are at risk. Affected deployments are customer-operated on-prem VCO installations, while the vendor-hosted (including Dedicated) VCO service was also impacted but has already been patched. No public proof of concept or in-the-wild exploitation has been reported, and the issue is not on CISA's KEV list.
Do: Update on-prem VCO to the fixed release specified in the Arista/Broadcom security advisory as soon as possible. Until patched, remove internet exposure by placing the orchestrator behind a VPN or IP allowlist, and audit logs for unauthenticated or anomalous API requests. Confirm hosted/Dedicated tenancies are on the current patched build and review managed edge devices for unauthorized configuration changes.
Unauthenticated Heap-Overflow RCE in F5 BIG-IP APM with OAuth Profile
F5 BIG-IP Access Policy Manager (APM) contains a heap-based buffer overflow (CWE-122) that is reachable when a virtual server has both an APM access policy and an OAuth profile configured. An unauthenticated remote attacker can send specifically crafted malicious traffic to such a virtual server and achieve remote code execution on the BIG-IP system, which fully compromises the confidentiality, integrity, and availability of the traffic-management device. Systems running in Appliance mode are also vulnerable, and because this is a data plane flaw, the exposure is at the virtual server itself rather than the management control plane. The vulnerability is rated critical (CVSS 4.0: 9.3) with no privileges or user interaction required. No public proof-of-concept or confirmed in-the-wild exploitation is known, and F5 has not evaluated software versions that have reached End of Technical Support.
Do: Inventory virtual servers with an APM access policy plus an OAuth profile and prioritize patching those first, applying the fixed release identified in F5's advisory (EoTS versions must be upgraded to a supported release to receive a fix). Until patched, remove the OAuth profile from internet-facing virtual servers where feasible or restrict access to the virtual server so untrusted sources cannot reach the APM listener. Monitor BIG-IP logs for anomalous traffic to APM-enabled virtual servers, since exploitation would not touch the management plane.
Stories merge articles from different outlets about the same event. The summary is rewritten by the model whenever new coverage arrives; individual articles keep their own summaries and full text.
largetens of thousands of internet-exposed Quantum VPN gateways (est.); total Check Point installed base plausibly in the hundreds of thousands of appliances/sites
KEV
large
likely tens of thousands (order of magnitude 10k–100k) of deployed Quantum gateways/management servers, of which a substantial share expose VPN endpoints to…
niche≈ several hundred internet-exposed on-prem VCO instances (order 10^2–10^3 total on-prem installs), each managing many SD-WAN edge devices
KEV
F5 BIG-IP (Access Policy Manager)
moderatelikely on the order of a few thousand internet-exposed virtual servers (subset of the tens of thousands of BIG-IP devices visible in public scans)