Vendor

Check Point

As of , 5 Check Point vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 4 were added in 2026. Patch first: CVE-2026-16232.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-16232Improper AuthenticationCheck Point SmartConsolePatch nowForensic triage required by CISA; Metasploit module0.78
2CVE-2026-93616Path TraversalCheck Point Multiple ProductsPatch nowForensic triage required by CISA0.20
3CVE-2026-85102Improper Certificate ValidationCheck Point Multiple ProductsPatch nowForensic triage required by CISA0.08
4CVE-2026-50751Improper AuthenticationCheck Point Security GatewayPatch nowRansomware use, listed within a year0.06
5CVE-2024-24919Information DisclosureCheck Point Quantum Security GatewaysPatch this weekRansomware use; Metasploit module; EPSS 0.990.99

Products

  • Multiple Products2 entries
  • Quantum Security Gateways1 entry
  • Security Gateway1 entry
  • SmartConsole1 entry

Added each year

12342024: 1120242025: nonenone20252026: 442026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20241
2025none
20264

Used in ransomware

Changes CISA made to these entries

  1. CVE-2026-50751 Check Point Security GatewayRansomware use: Unknown to Known.
  2. CVE-2024-24919 Check Point Quantum Security GatewaysEdited: notes.
  3. CVE-2024-24919 Check Point Quantum Security GatewaysRansomware use: Unknown to Known.

Every change we recorded