Attackers exploited a Check Point management-server flaw before its emergency fix
Check Point says CVE-2026-93616, a critical Management Server vulnerability, was exploited as early as July 23, 2026, prompting emergency fixes. The company also reported that attackers began probing CVE-2026-85102, a pre-authentication remote code execution flaw in Quantum Security Gateway, days after patches were released on September 9.
What changed For the separate Security Gateway flaw, Check Point reports a progression from patch release on September 9 to attacker probing a few days later—not confirmed successful exploitation.
Why it matters Management Server operators face a potential historical-compromise problem as well as a patching task: installing the emergency fix cannot establish whether a server was compromised earlier.
HelpNet Security ↗