CyberMax
Home › Exploited CVEs

Check Point known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 5 Check Point CVEs as exploited in the wild. 4 were added in the last 12 months (latest 2026-09-22), and 2 are known to be used in ransomware campaigns.

Check Point CVEs added to CISA KEV per year
2024: 1202412026: 420264

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Check Point products

Multiple Products (2), SmartConsole (1), Security Gateway (1), Quantum Security Gateways (1).

All Check Point CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-93616Multiple ProductsMultiple Products Path Traversal2026-09-222026-09-2519.7%–
CVE-2026-85102Multiple ProductsMultiple Products Improper Certificate Validation2026-09-222026-09-251.0%–
CVE-2026-16232SmartConsoleSmartConsole Improper Authentication2026-07-222026-07-2578.0%–
CVE-2026-50751Security GatewaySecurity Gateway Improper Authentication2026-06-082026-06-116.3%Yes
CVE-2024-24919Quantum Security GatewaysQuantum Security Gateways Information Disclosure2024-05-302024-06-20100.0%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors