Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Check Point Exploited CVEs 2026: VPN RCE CVE-2026-85102, Management Server CVE-2026-93616, IKEv1 Auth Bypass

Critical CVE-2026-85102, CVE-2026-93616, CVE-2026-16232, CVE-2026-50751 — Four Check Point Quantum vulnerabilities joined CISA's exploited list in 2026: an unauthenticated VPN code-execution bug, an unauthenticated script upload on Management Servers, a SmartConsole admin bypass, and an IKEv1 remote-access bypass used by ransomware. Jumbo Hotfix levels to install.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Check Point gateways and management servers have four exploited bugs this year: unauthenticated code execution on the gateway during VPN negotiation (CVE-2026-85102, CVSS 9.8), unauthenticated script upload and execution on the Management Server (CVE-2026-93616, 9.8), a SmartConsole token bypass to full admin (CVE-2026-16232), and a VPN login bypass in deprecated IKEv1 used by ransomware (CVE-2026-50751). Install the latest Jumbo Hotfix Accumulator on gateways and management.

CVE-2026-85102Gateway: certificate trust validation during VPN negotiation → unauthenticated RCE. CVSS 9.8. KEV 2026-09-22
CVE-2026-93616Management Server: directory traversal + file upload → unauthenticated script execution. CVSS 9.8. KEV 2026-09-22
CVE-2026-16232SmartConsole login: obtain an application token → full admin. CVSS 4.0: 9.3. KEV 2026-07-22
CVE-2026-50751Remote Access / Mobile Access over IKEv1: VPN without a valid password. Known ransomware use. KEV 2026-06-08
FixLatest Jumbo Hotfix Take for R82.10 / R82 / R81.20 (affected takes below); R81.10 and older are end of support

The four bugs

CVEWhereVulnerable at or below
CVE-2026-85102Quantum Security Gateway (VPN)R82.10 JHF Take 43 · R82 Take 125 · R81.20 Take 165
CVE-2026-93616Quantum Security Management ServerR82.20 with no JHF · R82.10 Take 44 · R82 Take 126 · R81.20 Take 166 · R81.10 Take 190 · R81
CVE-2026-16232Security Management / Multi-Domain (SmartConsole login)R82.10 Take 36 · R82 Take 118 · R81.20 Take 158 · all R81.10 and older
CVE-2026-50751Gateways and Spark firewalls with Remote Access / Mobile Access using IKEv1R82.10 Take 19 · R82 Take 103 · R81.20 Take 141 · R81.10/R81/R80.40; Spark R80.20.X/R81.10.X/R82.00.X

The gateway bug (85102) and the management bug (93616) each give code execution without logging in. The SmartConsole bypass (16232) is exploitable remotely when the Management Server is reachable from the internet and Trusted Clients isn’t restricted, which is a configuration Check Point has warned against for years.

Am I affected?

# On the gateway or management server (Expert mode)
cpinfo -y all | grep -i -E "HOTFIX|JUMBO"
# or in Clish
show installer packages installed

Compare the installed Jumbo Hotfix Take against the table. Anything at or below the listed Take is vulnerable.

How to patch

  1. Use CPUSE (Gaia Portal → Upgrades (CPUSE)) to install the latest recommended Jumbo Hotfix Accumulator for your version on every gateway and management server.
  2. For Spark appliances, update firmware from the local web UI or SMP.
  3. R81.10 and older are end of support; plan an upgrade to R81.20 or R82.x.

Mitigations

  • Disable IKEv1 for Remote Access if you still have it on. Check Point’s guidance is IKEv2-only (sk185033).
  • Restrict Trusted Clients on the Management Server to specific admin IPs, and don’t expose the management server’s ports (18190, 19009, 443 GAiA portal) to the internet.
  • Enforce MFA for Remote Access VPN users.

Check for compromise

  • Review VPN logs for Remote Access connections from users who don’t normally connect, or from unusual countries, especially with IKEv1.
  • Review SmartConsole audit logs for administrator logins and policy changes you can’t explain.
  • On the Management Server, look for unexpected files in web-accessible directories.
  • If compromised, rotate admin credentials, VPN certificates and any shared secrets the device holds.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories