CVE-2026-93616: Critical Unauthenticated RCE in Check Point Management Server
In September 2026, Check Point disclosed CVE-2026-93616, a critical unauthenticated remote code execution flaw affecting Security Management Server and Log Server versions R80.30 through R80.40 prior to hotfix CP‑HF‑2026‑09‑15. The vulnerability, scored CVSS v3.1 9.8, stems from insufficient input validation in the web‑based management interface’s file upload endpoint (/msa/upload.php), allowing an attacker to embed directory‑traversal sequences (e.g., \"../\") in the filename parameter, write arbitrary scripts outside the intended directory, and execute them with root privileges. Active exploitation has been observed in targeted attacks against high‑value enterprises, prompting emergency patches via LivePatch and advisories from Check Point, CISA, and multiple threat‑intel feeds.
Check Point Quantum VPN: Critical Certificate Validation Flaws Enable Unauthenticated RCE
In June 2026, Check Point disclosed two critical authentication bypass flaws (CVE‑2026-50751 CVSS 9.3, CVE‑2026-50752 CVSS 7.4) in Quantum VPN gateways that allow unauthenticated attackers to establish IKEv1 VPN sessions when legacy Remote Access clients are enabled and machine‑certificate validation is not enforced; post‑authentication steps can lead to privileged remote code execution. Active exploitation of CVE‑2026-50751 was observed from May 7 2026, linked to a Qilin ransomware affiliate, prompting urgent warnings from the Dutch NCSC and inclusion considerations for CISA’s KEV catalog.
Critical Authentication Bypass in Check Point SmartConsole CVE-2026-16232
CVE-2026-16232 is a critical authentication bypass vulnerability (CVSS 9.3) affecting Check Point SmartConsole and Security Management Servers. The flaw originates from a broken trust boundary in the authenticateRemoteApplication() function, where the server prioritizes an attacker-provided Secure Internal Communication (SIC) Distinguished Name (DN) over the verified peer certificate DN. This allows unauthenticated attackers to forge application identities and mint administrative Single Sign-On (SSO) tickets via SOAP APIs. Successful exploitation grants full administrative control over the management server and all downstream security gateways, enabling malicious policy modification and disabling of security auditing. Remediation requires applying the vendor's jumbo hotfix and implementing strict IP-based access controls.
Check Point Remote Access VPN: Authentication Bypass CVE-2026-50751
CVE-2026-50751 is a critical authentication bypass vulnerability (CVSS 9.3) affecting Check Point Remote Access VPN and Mobile Access deployments utilizing the deprecated IKEv1 protocol. A logic error within the iked daemon's process_cert_payloads function allows remote attackers to manipulate certificate validation flags, effectively bypassing signature verification to establish VPN sessions without valid credentials. The flaw has been actively exploited by Qilin ransomware affiliates to gain initial perimeter access to targeted organizations. Remediation requires the immediate application of the vendor-supplied hotfix to enforce policy-based validation and the decommissioning of IKEv1 in favor of IKEv2.
Check Point 2026 Exposure Gap Report: AI-Driven Vulnerability Inflation
The report identifies "AI-Driven Vulnerability Inflation," a phenomenon where AI-augmented threat actors and automated discovery tools have doubled the volume of critical CVE discoveries. This surge has significantly degraded the signal-to-noise ratio within Security Operations Centers (SOCs), as fewer than 8.3% (1 in 12) of reported critical vulnerabilities require immediate remediation. The disconnect between high-level AI security governance and actual technical enforcement capabilities is widening a critical "exposure gap," overwhelming frontline defenders with low-priority alerts and high-velocity exploit payloads generated via Large Language Models (LLMs).