Checkpoint: 2 Actively-Exploited Flaws Added to CISA KEV
CISA has added two Checkpoint vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming active exploitation of these flaws in the wild.

Key findings
- Two Checkpoint vulnerabilities, CVE-2026-85102 and CVE-2026-93616, added to CISA KEV.
- Both flaws are confirmed to be under active exploitation in the wild.
- No ransomware association has been reported for these specific CVEs.
- Immediate patching of affected Checkpoint products is critically important.
- CISA's KEV catalog highlights urgent remediation for all organizations.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert, adding two Checkpoint vulnerabilities, CVE-2026-85102 and CVE-2026-93616, to its authoritative Known Exploited Vulnerabilities (KEV) catalog. This inclusion, effective September 22, 2026, signifies that these security flaws are under active exploitation by malicious actors, posing immediate and significant risks to organizations utilizing affected Checkpoint products. The KEV catalog serves as a critical resource for federal agencies and is a strong indicator for all organizations to prioritize remediation efforts.
The two vulnerabilities are:
- **CVE-2026-85102**: A critical flaw affecting Checkpoint systems.
- **CVE-2026-93616**: Another significant vulnerability impacting Checkpoint infrastructure.
While specific exploit details are not publicly disclosed at the time of their KEV addition, their presence in the catalog underscores the urgency for immediate action.
Based on current intelligence, neither of these newly added Checkpoint vulnerabilities has been explicitly linked to ransomware campaigns. However, active exploitation of any vulnerability can lead to unauthorized access, data breaches, and further compromise of network infrastructure, regardless of whether ransomware is the ultimate payload. Organizations should not delay remediation based on the absence of a ransomware tag.
Defenders are strongly advised to identify and patch all instances of affected Checkpoint products immediately. CISA mandates that federal civilian executive branch agencies remediate KEV vulnerabilities within a specified timeframe, typically six months, but the confirmed active exploitation warrants much faster action for all organizations. Prioritizing patches for these actively exploited flaws is crucial to protect against ongoing threats and maintain a robust security posture.