Critical CVE-2026-85102, CVE-2026-93616, CVE-2026-16232, CVE-2026-50751 — Four Check Point Quantum vulnerabilities joined CISA's exploited list in 2026: an unauthenticated VPN code-execution bug, an unauthenticated script upload on Management Servers, a SmartConsole admin bypass, and an IKEv1 remote-access bypass used by ransomware. Jumbo Hotfix levels to install.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Check Point gateways and management servers have four exploited bugs this year: unauthenticated code execution on the gateway during VPN negotiation (CVE-2026-85102, CVSS 9.8), unauthenticated script upload and execution on the Management Server (CVE-2026-93616, 9.8), a SmartConsole token bypass to full admin (CVE-2026-16232), and a VPN login bypass in deprecated IKEv1 used by ransomware (CVE-2026-50751). Install the latest Jumbo Hotfix Accumulator on gateways and management.
| CVE-2026-85102 | Gateway: certificate trust validation during VPN negotiation → unauthenticated RCE. CVSS 9.8. KEV 2026-09-22 |
|---|---|
| CVE-2026-93616 | Management Server: directory traversal + file upload → unauthenticated script execution. CVSS 9.8. KEV 2026-09-22 |
| CVE-2026-16232 | SmartConsole login: obtain an application token → full admin. CVSS 4.0: 9.3. KEV 2026-07-22 |
| CVE-2026-50751 | Remote Access / Mobile Access over IKEv1: VPN without a valid password. Known ransomware use. KEV 2026-06-08 |
| Fix | Latest Jumbo Hotfix Take for R82.10 / R82 / R81.20 (affected takes below); R81.10 and older are end of support |
| CVE | Where | Vulnerable at or below |
|---|---|---|
| CVE-2026-85102 | Quantum Security Gateway (VPN) | R82.10 JHF Take 43 · R82 Take 125 · R81.20 Take 165 |
| CVE-2026-93616 | Quantum Security Management Server | R82.20 with no JHF · R82.10 Take 44 · R82 Take 126 · R81.20 Take 166 · R81.10 Take 190 · R81 |
| CVE-2026-16232 | Security Management / Multi-Domain (SmartConsole login) | R82.10 Take 36 · R82 Take 118 · R81.20 Take 158 · all R81.10 and older |
| CVE-2026-50751 | Gateways and Spark firewalls with Remote Access / Mobile Access using IKEv1 | R82.10 Take 19 · R82 Take 103 · R81.20 Take 141 · R81.10/R81/R80.40; Spark R80.20.X/R81.10.X/R82.00.X |
The gateway bug (85102) and the management bug (93616) each give code execution without logging in. The SmartConsole bypass (16232) is exploitable remotely when the Management Server is reachable from the internet and Trusted Clients isn’t restricted, which is a configuration Check Point has warned against for years.
# On the gateway or management server (Expert mode)
cpinfo -y all | grep -i -E "HOTFIX|JUMBO"
# or in Clish
show installer packages installed
Compare the installed Jumbo Hotfix Take against the table. Anything at or below the listed Take is vulnerable.
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.