PatchSiren

Check Point CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Check Point CVE published 2026-09-22

CVE-2026-93616

Check Point Multiple Products Path Traversal Vulnerability debrief. The vulnerability allows attackers to access sensitive files and directories. Defenders should assess exposure and apply mitigations. However, details on affected versions and exploitation are limited. This vulnerability is part of the CISA Known Exploited Vulnerabilities catalog, indicating its potential for exploitation in the wild. The [truncated]

Known exploited Check Point CVE published 2026-09-22

CVE-2026-85102

Check Point Multiple Products Improper Certificate Validation Vulnerability debrief. This vulnerability affects Check Point Multiple Products and allows attackers to perform man-in-the-middle attacks. Defenders should assess exposure and apply mitigations according to vendor instructions. The vulnerability has a high severity and requires immediate attention from defenders responsible for these products. [truncated]

Known exploited Check Point CVE published 2026-07-22

CVE-2026-16232

CVE-2026-16232 is an improper authentication vulnerability in Check Point SmartConsole. The vulnerability's details are limited, but it is known to be exploited. Check Point has provided guidance on mitigation. Security teams responsible for Check Point SmartConsole should assess and prioritize patching based on risk and compliance with CISA's BOD 26-04 guidance. The vulnerability may impact managed envir [truncated]

Known exploited Check Point CVE published 2026-06-08

CVE-2026-50751

CVE-2026-50751 is a critical vulnerability in Check Point Security Gateway, allowing for improper authentication. The vulnerability has a CVSS score of 9.3 and is considered critical. It was published on 2026-06-08 and has not been modified since its publication.

Known exploited Check Point CVE published 2024-05-30

CVE-2024-24919

CVE-2024-24919 is an information disclosure vulnerability affecting Check Point Quantum Security Gateways. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2024-05-30, which means it is considered actively exploited and time-sensitive for defenders. CISA also marks it as associated with known ransomware campaign use. Organizations should prioritize the vendor guidance referenced by CI [truncated]