The US Cybersecurity and Infrastructure Security Agency added four new vulnerabilities to its Known Exploited Vulnerabilities catalog on 22 September 2026, including critical Check Point path traversal and certificate validation flaws showing active exploitation. By 24 September, CISA added two additional exploited vulnerabilities.
10 reportsother · primary
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability CVE-2026-9412
Check Point Quantum Security Management is affected by CVE-2026-93616 (CRITICAL, CVSS 9.8): unauthenticated attackers can upload & execute scripts via path traversal. Restrict access & monitor activity until patch info is released. https:// radar.offseq.com/threat/cve-20 26-93616-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-4344dfa6a4d98182 # OffSeq # CheckP
🚨 Check Point patches Management Server zero-day exploited in attacks ⠀ Check Point has released fixes for CVE-2026-93616, a vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts on affected management servers. ⠀ The company says a small number of customers have already been attacked. ⠀ Affected products include: • Security Management Server • Multi-Domain Se
Two Check Point critical vulnerabilities are now listed as exploited in the wild. https:// ifin.network/t/cve-2026-85102- and-93616-check-point-security-gateway-rce-path-traversal-exploited/853 # ThreatIntel # ThreatIntelligence # IFIN
🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0922 ) CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to t