Check Point patched a critical flaw in its management servers that lets an unauthenticated attacker run code as root. Tracked as CVE-2026-91843 and scored 9.8, it is a stack overflow in the login process, which handles requests before a user authenticates, and it can be triggered by a login request carrying an overly long username. It affects Quantum management, Log, and Multi-Domain servers, through the Trusted Clients path. Customers with automatic updates are already protected, and others should apply the vendor's live patch. Check Point reports no exploitation yet, but this is the third serious management-server flaw it has disclosed in weeks, and compromising it means control over the whole firewall estate.
Check Point patched two critical flaws in how its firewall and management products handle VPN certificates, each scored 9.8, that could let an unauthenticated remote attacker run code. CVE-2026-85102 is improper certificate-trust validation during VPN negotiation that can lead to code execution on the Security Gateway. CVE-2026-85103 is a heap overflow while decoding a certificate's structure, affecting both the gateway and the management server. Notably, because the second flaw is about certificate processing, Check Point says it could be triggered even where VPN is not running, so management servers need the fix regardless. Check Point found the issues internally and reports no exploitation yet, though its products were attacked twice this year.
Check Point has fixed an actively exploited flaw in SmartConsole, the graphical admin panel used to manage its security products. CVE-2026-16232, rated 9.3, is an authentication bypass letting an unauthenticated remote attacker obtain a login token and authenticate with administrator privileges, after which they can alter security configuration and policy on a Security Management or Multi-Domain Management server. Exploitation requires the management server to be reachable from the internet with no restrictions on trusted GUI clients. The same update fixes a second critical authentication bypass and a Gaia Portal issue letting read-only users run commands as root.
Check Point has rushed out a fix for a critical flaw in its Remote Access VPN, Mobile Access, and Spark firewall products that attackers have been exploiting since May 7. The bug (CVE-2026-50751, rated 9.3) is a logic error in how the software checks certificates, letting an unauthenticated attacker log into the VPN with no password, but only on gateways still using the old IKEv1 key-exchange protocol. So far a few dozen organizations have been hit, and at least one intrusion was tied to an affiliate of the Qilin ransomware gang, which used the access to steal data with Rclone before deploying ransomware. A second, unexploited flaw was also patched.
The Gentlemen, the second most prolific public ransomware operation of 2026 with over 320 listed victims, has had its own internal database leaked. Check Point Research and others obtained the data after a breach of the group's hosting provider 4VPS exposed their Rocket backend. The leak unmasks roughly 9 named operators centered on an administrator known as zeta88 (aka hastalamuerte), who built the RaaS panel in three days using DeepSeek and Qwen AI coding assistants, runs payouts, and joins encryption events personally. Internal chats also confirm chain-victimization: in April the group hit a UK software consultancy and then weaponized stolen client credentials to compromise one of the consultancy's customers in Turkey.