Exploitation timeline
Threadlinqs has recorded 8 checkpoint CVEs published between and . The busiest month was 2026-09 (4 new CVEs). 2 of them (25%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 8 of 8 tracked checkpoint CVEs.
- CVE-2026-93616critical 9.8KEVEPSS 2.4%
- CVE-2026-16232critical 9.1KEVEPSS 1.1%
- CVE-2026-62144critical 9.1EPSS 1%
- CVE-2026-62145high 7.5EPSS 0.4%
- CVE-2026-85103critical 9.8EPSS 0.4%
- CVE-2026-85102critical 9.8EPSS 0.3%
- CVE-2026-91843critical 9.8
- CVE-2026-18574critical 9.3
Products affected
Threadlinqs normalises CPE and CNA product records across all 8 CVEs; 5 distinct checkpoint products are affected. The most frequently affected:
- Quantum Security Management 6 CVEs
- Quantum Security Gateway 3 CVEs
- Multi-Domain Security Management 2 CVEs
- Multi-Domain Security Management Server 1 CVE
- Security Management Server 1 CVE
Threat activity
14 tracked threat campaigns reference checkpoint products or exploit checkpoint CVEs:
- Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day (CVE-2026-93616) Actively ExploitedCRITICAL
- CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud Orchestrator Auth Bypass, F5 BIG-IP APM Heap OverflowCRITICAL
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)CRITICAL
- Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)CRITICAL
- Critical Check Point Management Server Flaw (CVE-2026-91843) Lets Unauthenticated Attackers Run Code as RootCRITICAL
- Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected ImminentlyCRITICAL
- Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter DevicesHIGH
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)HIGH
- Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command Execution on Security Management ServerCRITICAL
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote AccessMEDIUM
- CVE-2026-16232: Check Point SmartConsole Authentication Bypass Actively Exploited, Added to CISA KEVCRITICAL
- ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security ResearchersHIGH
- ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security ResearchersHIGH
- Check Point Remote Access & Mobile Access VPN IKEv1 Authentication Bypass (CVE-2026-50751) Exploited by Qilin Ransomware AffiliateCRITICAL
Threat actors targeting checkpoint
Named threat actors attributed to campaigns that involve checkpoint products or CVEs, with the number of linked campaigns:
How to prioritise checkpoint patching
This order follows the data Threadlinqs holds for checkpoint, not a generic severity checklist:
- 2 of 8 checkpoint CVEs (25%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2026-93616, CVE-2026-16232.
- Outside KEV, the highest EPSS scores are CVE-2026-62144 (1%), CVE-2026-62145 (0.4%), CVE-2026-85103 (0.4%).
- 7 CVEs score Critical and 1 High on CVSS v3 (maximum 9.8, average 9.3); sequence these after KEV and high-EPSS items.
- 3 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.