Check Point patched two critical VPN vulnerabilities (CVE-2026-85102 and CVE-2026-85103) with CVSS scores of 9.8 that allow unauthenticated remote code execution in Security Gateway and Management Server products. As of September 14, 2026, the Dutch NCSC warned that exploitation of the flaws was imminent, prompting urgent action for internet-facing VPN gateway administrators.
Check Point fixed a critical Check Point login flaw (CVE-2026-91843). Patch this Check Point login flaw now to block unauthenticated remote root takeovers.
Check Point's SmartConsole GUI admin panel has an actively exploited zero-day authentication bypass (CVE-2026-16232, CVSS 9.3) that grants full admin access to Security Management servers; a patch has been released. Cisco's Secure FMC also faces an actively exploited zero-day involving static credentials.
Check Point Software disclosed CVE-2026-91843, a pre-authentication stack overflow vulnerability (CVSS 9.8) in Security Management servers enabling unauthenticated attackers to execute code with root privileges. The flaw affects management and log servers with no known active exploitation as of 2026-09-18.
Dutch NCSC warns of imminent Check Point VPN exploits Critical flaws in Check Point VPN may be targeted soon, Dutch authorities say https:// hostingpaper.com/article/dutch -ncsc-warns-of-imminent-check-point-vpn-exploits # Security # Vulnerabilities
Check Point confirmed active exploitation of CVE-2026-16232, a critical authentication bypass in SmartConsole with a CVSS score of 9.3. The flaw allows unauthenticated attackers to gain full administrative access, with CISA setting a July 25 patch deadline for federal agencies.
Check Point released emergency patches on September 22, 2026, for CVE-2026-93616, a critical zero-day vulnerability in Security Management Server products that attackers actively exploited in targeted attacks beginning in July. By September 24, the company confirmed active exploitation of three critical vulnerabilities affecting VPN Gateways and Management Servers.
Root-Sicherheitslücke gefährdet Check Point Security Management and Log Servers https://www.heise.de/news/Root-Sicherheitsluecke-gefaehrdet-Check-Point-Security-Management-and-Log-Servers-11457947.html?utm_source=flipboard&utm_medium=activitypub Posted into Heise Security […]
Various unrelated cybersecurity incidents were disclosed including CISA warnings about Check Point authentication vulnerabilities and Rockwell PLC exploits by Iran-linked hackers, Chick-fil-A credential compromise, and a Bluetooth vulnerability affecting 2.2 million vehicles. These represent distinct incidents across different sectors with no unified narrative.
The US Cybersecurity and Infrastructure Security Agency added four new vulnerabilities to its Known Exploited Vulnerabilities catalog on 22 September 2026, including critical Check Point path traversal and certificate validation flaws showing active exploitation. By 24 September, CISA added two additional exploited vulnerabilities.
Cybersecurity company Check Point confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution vulnerability in Security Gateway VPN certificate handling, as of 2026-09-24. The firm warned administrators to patch immediately or apply workarounds.
Between September 8 and 10, 2026, critical security vulnerabilities were disclosed in Fortinet (CVE-2026-84390, CVE-2026-26084), Siemens (CVE-2026-18963, CVE-2026-50093), Apache Nutch (CVE-2026-41870), Apache Artemis (CVE-2026-67593), NVIDIA Triton, and NextGen Healthcare Mirth Connect, exposing systems to account takeover, remote code execution, denial of service, and data exfiltration.
German cybersecurity authority CERT-Bund published advisories on 2026-09-11 for critical vulnerabilities across six major software products: Linux Kernel, Joplin, Palo Alto Networks Cortex XDR, Langflow, Angular, and MongoDB, all rated high-severity with network-accessible attack vectors.
Between 2026-09-22 and 2026-09-24, multiple remote code execution vulnerabilities were disclosed in Android Telecom (CVE-2026-49881), Check Point Management (CVE-2026-93616), Check Point VPN (CVE-2026-85102), ManageEngine OpManager (CVE-2026-19599), GitLab (CVE-2026-89078), and Luxion KeyShot (CVE-2026-92202). Several are actively exploited in the wild.
Cluster aggregates six separate cybersecurity incidents: Check Point SmartConsole vulnerability, Google record fine, Windows NT kernel PoC, Iranian attacks on Rockwell PLCs, South Korean diplomatic academy breach, and AWS vulnerability. Events share only time period and source feed, not a narrative.
Check Point Software released emergency hotfixes on September 22, 2026, to address a critical Security Management Server vulnerability being actively exploited in attacks. The flaw allows attackers to run arbitrary scripts on affected systems.
From Check Point Research: Check Point Research has assessed # ransomware activity during Q2 2026, identifying 2,139 publicly reported victims, up 33% year over year. The ransomware ecosystem expanded to 93 active groups, while leaked communications showed The Gentlemen using AI coding assistants to accelerate development of operational tooling.