Check Point known exploited vulnerabilities
CISA lists 5 Check Point CVEs as exploited in the wild. 4 were added in the last 12 months (latest 2026-09-22), and 2 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2024-24919 (Quantum Security Gateways): EPSS 100.0%, added 2024-05-30
- CVE-2026-16232 (SmartConsole): EPSS 78.0%, added 2026-07-22
- CVE-2026-93616 (Multiple Products): EPSS 19.7%, added 2026-09-22
- CVE-2026-50751 (Security Gateway): EPSS 6.3%, added 2026-06-08
- CVE-2026-85102 (Multiple Products): EPSS 1.0%, added 2026-09-22
Most affected Check Point products
Multiple Products (2), SmartConsole (1), Security Gateway (1), Quantum Security Gateways (1).
All Check Point CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-93616 | Multiple Products | Multiple Products Path Traversal | 2026-09-22 | 2026-09-25 | 19.7% | – |
| CVE-2026-85102 | Multiple Products | Multiple Products Improper Certificate Validation | 2026-09-22 | 2026-09-25 | 1.0% | – |
| CVE-2026-16232 | SmartConsole | SmartConsole Improper Authentication | 2026-07-22 | 2026-07-25 | 78.0% | – |
| CVE-2026-50751 | Security Gateway | Security Gateway Improper Authentication | 2026-06-08 | 2026-06-11 | 6.3% | Yes |
| CVE-2024-24919 | Quantum Security Gateways | Quantum Security Gateways Information Disclosure | 2024-05-30 | 2024-06-20 | 100.0% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors