Vendor
Check Point vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 16 vulnerabilities in Check Point: 1 in the last 7 days and 7 in the last 90 days, 6 of them critical and 4 exploited in the wild. The most recent, CVE-2026-93616, was published on 22 September 2026. 2 technologies have a page of their own.
- Last 7 days
- 1
- Last 90 days
- 7
- Critical, all time
- 6
- Exploited in the wild
- 4
About Check Point
A global provider of cybersecurity solutions for corporate enterprises and governments.
Check Point technologies
Latest Check Point vulnerabilities
- CVE-2026-93616: A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary…criticalexploited in the wildCVSS 9.8EPSS 19.7%
- CVE-2026-91843: Check Point Security Management and Log Servers stack overflow in logincriticalCVSS 9.8EPSS 0.5%
- CVE-2026-85103: Check Point Quantum Security heap buffer overflow in VPN certificate ASN.1 decodingcriticalCVSS 9.8EPSS 3.6%
- CVE-2026-85102: Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an…criticalexploited in the wildCVSS 9.8EPSS 1.0%
- CVE-2026-62145: Check Point Gaia Portal privilege escalation to roothighCVSS 7.5
- CVE-2026-62144: Check Point Security Management authentication bypass in Management Serverinfo
- CVE-2026-16232: Check Point SmartConsole authentication bypass in login processcriticalexploited in the wildCVSS 9.8
- CVE-2026-10847: Check Point Identity Agent privilege escalation in log collectionhighCVSS 7.8
- CVE-2026-50752: Check Point VPN certificate validation bypass in IKEv1highCVSS 7.4
- CVE-2026-50751: Check Point VPN authentication bypass in IKEv1 key exchangecriticalexploited in the wildCVSS 9.8EPSS 0.0%
- CVE-2026-48136: Check Point Multi-Domain Management RBAC bypass in Compliance metadatamediumCVSS 4.1
- CVE-2026-48135: Check Point HTTP service heap overflow in request parsingmediumCVSS 5.3
- CVE-2026-48134: Check Point Security Gateway SQL injection in UserCheck PortalhighCVSS 7.6
- CVE-2026-48133: Check Point Security Gateway LFI in Identity Awareness bladehighCVSS 7.5
- CVE-2026-48132: Check Point Security Gateway denial of service in VPN servicehighCVSS 7.4
- CVE-2026-48131: Check Point VPN heap overflow in VPND IKE fragment reassemblyhighCVSS 8.1
Most severe Check Point vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-93616: A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary…criticalexploited in the wildCVSS 9.8EPSS 19.7%
- CVE-2026-85102: Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an…criticalexploited in the wildCVSS 9.8EPSS 1.0%
- CVE-2026-50751: Check Point VPN authentication bypass in IKEv1 key exchangecriticalexploited in the wildCVSS 9.8EPSS 0.0%
- CVE-2026-16232: Check Point SmartConsole authentication bypass in login processcriticalexploited in the wildCVSS 9.8
- CVE-2026-85103: Check Point Quantum Security heap buffer overflow in VPN certificate ASN.1 decodingcriticalCVSS 9.8EPSS 3.6%
- CVE-2026-91843: Check Point Security Management and Log Servers stack overflow in logincriticalCVSS 9.8EPSS 0.5%
- CVE-2026-48131: Check Point VPN heap overflow in VPND IKE fragment reassemblyhighCVSS 8.1
- CVE-2026-10847: Check Point Identity Agent privilege escalation in log collectionhighCVSS 7.8
- CVE-2026-48134: Check Point Security Gateway SQL injection in UserCheck PortalhighCVSS 7.6
- CVE-2026-62145: Check Point Gaia Portal privilege escalation to roothighCVSS 7.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 3 | 1 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 2 | 2 | |
| 14 Sep 2026 | 1 | 1 | |
| 21 Sep 2026 | 1 | 1 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/check-point.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Check Point vulnerabilities", https://junglewise.ai/threats/vendors/check-point, 26 September 2026.