Two critical, actively exploited vulnerabilities in Check Point products expose both security-management infrastructure and Quantum Security Gateways to unauthenticated remote code execution. CVE-2026-93616 (CVSS 9.8) affects Quantum Security Management and Multi-Domain Security Management releases R80 through R82.20: forged application authentication, directory traversal, and arbitrary file upload through CPM SOAP services on TCP/19009 can be chained to write files as root and execute commands. Bishop Fox demonstrated root-level exploitation on unpatched R81.10 and R82.10 systems by overwriting a cron file; LivePatch Takes 28 and 29 do not fix the issue. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 22.
CVE-2026-85102 (CVSS 9.8) affects Gaia OS and Gaia Embedded on Quantum Security Gateways, where improper certificate validation during VPN negotiation can enable unauthenticated code execution. Affected versions include R82.10 with Jumbo Hotfix Take 43 or earlier, R82 with Take 125 or earlier, and R81.20 with Take 165 or earlier; it is also in CISA's KEV catalog. Organizations should immediately deploy Check Point hotfix sk1000171 for the management-server flaw and sk1000117 or applicable fixed Gaia Embedded releases for the gateway flaw, restrict TCP/19009 and IKE/VPN negotiation to trusted administrative hosts and peers, and hunt for pre-patch compromise. For potentially exposed management servers, review file integrity and execution telemetry and rotate credentials and certificates.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Check Point disclosed CVE-2026-93616 in advisory sk1000171. The actively exploited flaw enables unauthenticated remote root-level code execution on Security Management Server and Multi-Domain Management Server; fixes were made available through specified Jumbo Hotfix Accumulator releases and an R82.20 Security Hotfix.
Brazil's CTIR Gov issued a TLP:CLEAR alert for the actively exploited Check Point Quantum Security Gateway remote-code-execution vulnerability. It identified affected Jumbo Hotfix release ranges and called for immediate deployment of vendor corrections.
Bishop Fox reproduced an end-to-end exploit against unpatched R81.10 and R82.10 management servers. The exploit combines forged application authentication and directory traversal to write files as root, demonstrating root command execution by overwriting a cron configuration file.
CSIRT Panamá issued public notices covering CVE-2026-93616 and CVE-2026-85102, both rated CVSS 9.8. It urged organizations to apply Check Point hotfixes, restrict exposed management or VPN interfaces, and investigate for compromise predating remediation.
CISA added CVE-2026-93616 and CVE-2026-85102 to its Known Exploited Vulnerabilities catalog, reflecting active exploitation. CVE-2026-93616 affects Check Point management products, while CVE-2026-85102 affects Gaia OS and Gaia Embedded on Quantum Security Gateways.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
gov.br
Open sourcebishopfox.com
Open sourcecert.pa
Open sourcecert.pa
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.