CISA added two Check Point vulnerabilities to its Known Exploited Vulnerabilities catalog on September 22, 2026, both scored CVSS 3.1 9.8 by NVD and both reachable without authentication. CVE-2026-85102 hits the firewall itself, Quantum Security Gateway, during VPN negotiation. CVE-2026-93616 hits Check Point Management Server. VulnCheck’s KEV feed reports the same exploitation status and date for both.
Check Point published a single security advisory post covering both CVEs, linked from both NVD records.
| CVE | Component | Weakness | CVSS | CISA KEV added |
|---|---|---|---|---|
| CVE-2026-85102 | Quantum Security Gateway | CWE-295, improper certificate validation | 9.8 | 2026-09-22 |
| CVE-2026-93616 | Quantum Security Management | CWE-22, path traversal | 9.8 | 2026-09-22 |
CVE-2026-85102: certificate trust failure in gateway VPN negotiation
The CVE record describes improper certificate trust validation during VPN negotiation that may allow an unauthenticated remote attacker to execute arbitrary code on the gateway. The record was published September 9, 2026, thirteen days before CISA listed it.
This is a separate issue from CVE-2026-50752, the IKEv1 certificate-validation flaw on the same gateway product we covered on September 20. That one requires a man-in-the-middle position and, as of that September 20 coverage, was reported exploited by VulnCheck alone. CVE-2026-85102 is scored with low attack complexity rather than CVE-2026-50752’s high, and its described outcome is code execution rather than tunnel interception.
CVE-2026-93616: unauthenticated script upload on the Management Server
The CVE record describes a combined directory traversal and file upload weakness that lets an unauthenticated attacker upload and run arbitrary scripts on the Check Point Management Server. NVD and CISA classify it as CWE-22. This record was published September 22, the same day CISA listed it.
It carries the same 9.8 score as the gateway flaw.
Evidence and confidence
- High confidence — exploitation status for both CVEs, reported independently by CISA KEV and VulnCheck KEV, both dated September 22, 2026.
- High confidence — each CVE’s CWE classification, which NVD, CVE.org, CISA KEV and VulnCheck all agree on.
- Medium confidence — both 9.8 scores and the shared vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), which come from NVD alone in our ingestion. - Not yet available — no FIRST EPSS score is in our ingestion for either CVE.
CISA’s and VulnCheck’s product field reads “Multiple Products” for both entries, while CVE.org names the specific component. That is a difference in granularity rather than a disagreement, and we use the CVE.org component names above.
Why this matters
Both flaws are unauthenticated and confirmed exploited. Our assessment: where VPN negotiation is exposed to the internet, patch the gateway first, then the management server, and confirm the management server is not reachable from untrusted networks.
CISA KEV listing puts both CVEs under Binding Operational Directive 26-04 for in-scope federal agencies, and CISA’s entries point to its Forensics Triage Requirements. For an internet-facing gateway or management server that was unpatched before the September 22 KEV listing, that means checking for compromise, not only applying the fix.
Frequently Asked Questions
Are CVE-2026-85102 and CVE-2026-93616 being actively exploited? Yes. CISA listed both in its Known Exploited Vulnerabilities catalog on September 22, 2026, and VulnCheck’s KEV feed reports the same for each.
Which Check Point products are affected? Quantum Security Gateway for CVE-2026-85102 and the Quantum Security Management server for CVE-2026-93616, per the CVE records.
Do attackers need credentials? No. Both CVE records describe the flaws as exploitable by an unauthenticated attacker.
Is CVE-2026-85102 the same as the earlier IKEv1 certificate bug? No. CVE-2026-50752 is a separate, lower-severity (CVSS 7.4) certificate-validation issue on the same gateway product, which our September 20 coverage describes as requiring a man-in-the-middle position.
Where are the fixes? Our source data does not carry fixed-version fields. Check Point’s support articles sk1000117 (CVE-2026-85102) and sk1000171 (CVE-2026-93616) are the vendor’s remediation references.
Severity, vectors and weakness classifications from the National Vulnerability Database records for CVE-2026-85102 and CVE-2026-93616, with component names from CVE.org. Exploitation status and the September 22, 2026 catalog date from CISA’s Known Exploited Vulnerabilities catalog entries for CVE-2026-85102 and CVE-2026-93616, independently corroborated by VulnCheck KEV. Vendor references: Check Point security advisory post, sk1000117, sk1000171. Aggregated September 24, 2026. See more vulnerability intelligence.