Skip to content
Cybersecurity

CISA Adds Two Exploited Check Point Flaws to Known Vulnerabilities List

CISA adds two exploited Check Point vulnerabilities to its KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two Check Point vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after evidence showed that attackers were exploiting the flaws in the wild. The vulnerabilities, tracked as CVE-2026-85102 and CVE-2026-93616, were added on September 22 with a federal remediation deadline of September 25.

Check Point had previously confirmed active exploitation of both vulnerabilities. The issues affect security gateways, VPN infrastructure and several centralized management products.

Two Check Point Vulnerabilities Under Attack

CVE-2026-85102 is an improper certificate-validation vulnerability affecting Check Point Security Gateway and Spark Firewall products using Site-to-Site or Remote Access VPN. CISA says an unauthenticated remote attacker could exploit the flaw to execute arbitrary code on an affected gateway.

The second vulnerability, CVE-2026-93616, is a path-traversal flaw affecting Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent. It can allow an unauthenticated attacker to upload and execute arbitrary scripts.

Check Point Confirms Exploitation

Check Point has reported exploitation attempts involving both vulnerabilities. For CVE-2026-85102, the company observed a wave of attacks against Spark customers beginning September 12, with activity originating from anonymization infrastructure such as VPN services and proxies.

CVE-2026-93616 has a longer exploitation history. Check Point reported that attackers had exploited the management-server vulnerability as a zero-day as early as July 23. The company also said it was aware of customers who had been attacked through the flaw.

CISA Sets September 25 Deadline

Both vulnerabilities were added to the KEV Catalog on September 22, with September 25 listed as the remediation deadline for federal civilian agencies under CISA's vulnerability-management requirements. CISA also requires forensic triage for these vulnerabilities under the applicable federal directive.

Although the directive applies specifically to U.S. federal civilian agencies, CISA encourages other organizations to use the KEV Catalog when prioritizing vulnerability remediation.

Organizations Urged to Check Exposed Systems

Security teams using affected Check Point products should identify vulnerable systems, apply the vendor-provided fixes or mitigations and review systems for indicators of compromise. Check Point has released updates addressing both vulnerabilities.

The inclusion of the flaws in CISA's KEV Catalog highlights the difference between a newly disclosed vulnerability and one with confirmed real-world exploitation. Organizations running affected Check Point infrastructure therefore need to account for both patching and potential prior compromise during their response.