# checkpoint vulnerabilities & exploitation

**CISA KEV**

> As of 2026-10-05, Threadlinqs tracks 8 checkpoint CVEs, 2 in the CISA Known Exploited Vulnerabilities catalog, linked to 14 tracked threat campaigns and 10 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 8 checkpoint CVEs published between 2026-07-15 and 2026-09-15. The busiest month was 2026-09 (4 new CVEs). 2 of them (25%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 8 of 8 tracked checkpoint CVEs.

- [CVE-2026-93616](https://intel.threadlinqs.com/cve/CVE-2026-93616) — CRITICAL 9.8 · KEV · EPSS 2.4% · 2026-09-22
- [CVE-2026-16232](https://intel.threadlinqs.com/cve/CVE-2026-16232) — CRITICAL 9.1 · KEV · EPSS 1.1% · 2026-07-22
- [CVE-2026-62144](https://intel.threadlinqs.com/cve/CVE-2026-62144) — CRITICAL 9.1 · EPSS 1% · 2026-07-22
- [CVE-2026-62145](https://intel.threadlinqs.com/cve/CVE-2026-62145) — HIGH 7.5 · EPSS 0.4% · 2026-07-22
- [CVE-2026-85103](https://intel.threadlinqs.com/cve/CVE-2026-85103) — CRITICAL 9.8 · EPSS 0.4% · 2026-09-09
- [CVE-2026-85102](https://intel.threadlinqs.com/cve/CVE-2026-85102) — CRITICAL 9.8 · EPSS 0.3% · 2026-09-09
- [CVE-2026-91843](https://intel.threadlinqs.com/cve/CVE-2026-91843) — CRITICAL 9.8 · 2026-09-16
- [CVE-2026-18574](https://intel.threadlinqs.com/cve/CVE-2026-18574) — CRITICAL 9.3 · 2026-08-03

## Products affected

Threadlinqs normalises CPE and CNA product records across all 8 CVEs; 5 distinct checkpoint products are affected. The most frequently affected:

- Quantum Security Management — 6 CVEs
- Quantum Security Gateway — 3 CVEs
- Multi-Domain Security Management — 2 CVEs
- Multi-Domain Security Management Server — 1 CVE
- Security Management Server — 1 CVE

## Threat activity

14 tracked threat campaigns reference checkpoint products or exploit checkpoint CVEs:

- [Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day (CVE-2026-93616) Actively Exploited](https://intel.threadlinqs.com/threat/TL-2026-2677) — CRITICAL — 2026-09-26
- [CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud Orchestrator Auth Bypass, F5 BIG-IP APM Heap Overflow](https://intel.threadlinqs.com/threat/TL-2026-2678) — CRITICAL — 2026-09-26
- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)](https://intel.threadlinqs.com/threat/TL-2026-2630) — CRITICAL — 2026-09-23
- [Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)](https://intel.threadlinqs.com/threat/TL-2026-2617) — CRITICAL — 2026-09-22
- [Critical Check Point Management Server Flaw (CVE-2026-91843) Lets Unauthenticated Attackers Run Code as Root](https://intel.threadlinqs.com/threat/TL-2026-2557) — CRITICAL — 2026-09-18
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected Imminently](https://intel.threadlinqs.com/threat/TL-2026-2463) — CRITICAL — 2026-09-12
- [Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter Devices](https://intel.threadlinqs.com/threat/TL-2026-2153) — HIGH — 2026-08-26
- [2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)](https://intel.threadlinqs.com/threat/TL-2026-2125) — HIGH — 2026-08-23
- [Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command Execution on Security Management Server](https://intel.threadlinqs.com/threat/TL-2026-1855) — CRITICAL — 2026-08-03
- [Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1774) — MEDIUM — 2026-07-27
- [CVE-2026-16232: Check Point SmartConsole Authentication Bypass Actively Exploited, Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1650) — CRITICAL — 2026-07-23
- [ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1062) — HIGH — 2026-07-02
- [ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1125) — HIGH — 2026-07-01
- [Check Point Remote Access & Mobile Access VPN IKEv1 Authentication Bypass (CVE-2026-50751) Exploited by Qilin Ransomware Affiliate](https://intel.threadlinqs.com/threat/TL-2026-0718) — CRITICAL — 2026-06-08

## Threat actors targeting checkpoint

Named threat actors attributed to campaigns that involve checkpoint products or CVEs, with the number of linked campaigns:

- [Qilin ransomware affiliate](https://intel.threadlinqs.com/actor/Qilin%20ransomware%20affiliate) — 2 campaigns
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1 campaign
- [Clop](https://intel.threadlinqs.com/actor/Clop) — 1 campaign
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 1 campaign
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 1 campaign
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 1 campaign
- [Play - G1040](https://intel.threadlinqs.com/actor/Play%20-%20G1040) — 1 campaign
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 1 campaign
- [Sinobi](https://intel.threadlinqs.com/actor/Sinobi) — 1 campaign
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 1 campaign

## How to prioritise checkpoint patching

This order follows the data Threadlinqs holds for checkpoint, not a generic severity checklist:

- 2 of 8 checkpoint CVEs (25%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2026-93616](https://intel.threadlinqs.com/cve/CVE-2026-93616), [CVE-2026-16232](https://intel.threadlinqs.com/cve/CVE-2026-16232).
- Outside KEV, the highest EPSS scores are [CVE-2026-62144](https://intel.threadlinqs.com/cve/CVE-2026-62144) (1%), [CVE-2026-62145](https://intel.threadlinqs.com/cve/CVE-2026-62145) (0.4%), [CVE-2026-85103](https://intel.threadlinqs.com/cve/CVE-2026-85103) (0.4%).
- 7 CVEs score Critical and 1 High on CVSS v3 (maximum 9.8, average 9.3); sequence these after KEV and high-EPSS items.
- 3 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/checkpoint
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
