Brazil warns on Check Point, Fortinet
Brazil’s CTIR Gov added a critical alert on Check Point Quantum Security Gateway. Fortinet, GitLab and Stockagile also drew notices.
Brazil’s CTIR Gov issued a critical alert on Check Point Quantum Security Gateway and urged immediate vendor fixes. At the same time, CISC confirmed active exploitation of a Fortinet authentication bypass, while INCIBE-CERT kept its warnings on GitLab and Stockagile.
Update October 6, 2026: Brazil’s CTIR Gov added Alert 91/2026 for a critical flaw in Check Point Quantum Security Gateway and urged immediate application of the vendor’s fixes. New technical analysis also linked two Check Point issues to unauthenticated remote code execution and post-patch exploitation.
Between September 25 and October 6, CTIR Gov in Brazil published several security alerts covering critical flaws in Fortinet, Cisco Identity Services Engine, Adobe Commerce and Magento, and Check Point Quantum Security Gateway. In parallel, Spain’s INCIBE-CERT issued advisories on 11 GitLab vulnerabilities and seven in Stockagile, while Brazil’s CISC bulletin included active exploitation of an authentication bypass in Fortinet devices.
What did Brazil’s CTIR Gov fix?
CTIR Gov issued Alert 86/2026 for an update that fixes a critical flaw in multiple Fortinet products, Alert 87/2026 for Cisco Identity Services Engine, Alert 85/2026 for Adobe Commerce and Magento, and Alert 91/2026 for Check Point Quantum Security Gateway. In the Check Point case, the Brazilian agency recommended applying the vendor’s fixes immediately because of the potential for arbitrary code execution by a remote attacker.
In Fortinet’s case, advisory 86/2026 identifies CVE-2025-25249, says it affects FortiOS and FortiSwitchManager among other products, and lists it in the CISA KEV catalog. The same document reports an EPSS score of 3.86%. Alert 86/2026 was published on September 25, 2026.
What happened with Check Point?
New advisories and technical analysis expanded the Check Point case, with two vulnerabilities affecting both Quantum Security Gateway and Security Management. Threat Frontier reported that CVE-2026-85102 affects certificate validation during VPN negotiation and can allow unauthenticated remote code execution.
According to that analysis, attackers began using CVE-2026-85102 three days after the patch was released. Safe Security described the same flaw as a pre-authentication remote code execution issue in VPN certificate handling and linked it to CVE-2026-93616, which affects the Security Management web service through path traversal and file upload.
Bishop Fox published a technical analysis of CVE-2026-93616 and said it allows unauthenticated remote code execution as root against Check Point’s management server through a single TCP port. That server holds the firewall policy and the organization’s internal certificate authority. The Isle of Man government, meanwhile, issued a separate advisory saying Check Point had documented active exploitation of a vulnerability in Management Server that allows arbitrary scripts to be uploaded and executed.
What did Brazil’s bulletins say about Fortinet?
Brazil’s CISC Vulnerability Bulletin included a section on active exploitation of an authentication bypass in Fortinet devices, identified as CVE-2025-20265. The text explicitly uses the phrase "Exploração Ativa de Bypass de Autenticação em Dispositivos Fortinet (Patch Bypass)", confirming active exploitation in that advisory.
The same bulletin also listed alerts for CVE-2026-42031 in CKAN DataStore, CVE-2026-44277 in Fortinet FortiAuthenticator, six zero-day vulnerabilities in Microsoft Windows, a critical code execution issue in 7-Zip, an authentication bypass in Check Point Remote Access VPN, and multiple critical vulnerabilities in NGINX.
What happened with GitLab and Stockagile?
INCIBE-CERT issued an advisory for 11 GitLab vulnerabilities, two of them critical, and recommended updating to GitLab 19.2.7 or later, 19.3.3 or later, and 19.4.1 or later depending on the installed branch. Forest Watch reported that GitLab released emergency patches 19.4.1, 19.3.3 and 19.2.7 for Community and Enterprise, which fix 11 vulnerabilities, including two critical flaws rated CVSS 9.9.
Official CVE records tie those critical flaws to CVE-2026-89078, a double free issue when parsing a crafted regular expression in a CI/CD configuration, and CVE-2026-93577, an integer overflow in the same context. In both cases, under certain conditions, an authenticated user could execute arbitrary code on the GitLab server. Another record, CVE-2026-92530, describes an issue that could let an attacker impersonate pull request authorship during Direct Transfer imports.
For Stockagile, INCIBE-CERT warned about seven medium-severity vulnerabilities and said that, for now, no fix had been reported and no known exploitation attempts existed.
What regional scope do these advisories leave?
The materials published by CTIR Gov, CISC and INCIBE-CERT show a recent wave of advisories centered on products widely used in corporate and infrastructure environments. Brazil concentrated alerts on Fortinet, Check Point, Cisco and Adobe, while Spain, through INCIBE-CERT, reported on GitLab and Stockagile with update guidance and, in the second case, no available fix at the time of the advisory.
Sources
- Check Point CVE-2026-93616 Management RCE Exploitedthreatfrontier.com· Threat Frontier
- One Port to Root: Weaponizing Check Point Management…bishopfox.com· Bishop Fox
- Vulnerability Notice: Citrix, F5 & Check Pointcsc.gov.im· Cyber Security Centre, Isle of Man Government
- Boletim do CISC de Vulnerabilidadesgov.br· CISC / gov.br
- ALERTA 91/2026gov.br· CTIR Gov / gov.br
- This Week's CVE Priorities: Citrix, Check Point, F5, Cisco and PeopleSoft Under Active Exploitationsafe.security· Safe Security
- ALERTA 87/2026gov.br· Governo Federal do Brasil / CTIR Gov
- CVE-2026-92530 - CVE Recordcve.org· CVE.org
- INCIBE-CERT alerta de siete vulnerabilidades de severidad mediamoncloa.com· Moncloa
- 「GitLab」に再び緊急パッチ、CVSS基本値「9.9」の脆弱性2件に対処forest.watch.impress.co.jp· Forest Watch / Impress Watch
- CVE-2026-89078 - CVE Recordcve.org· CVE.org
- ALERTA 85/2026gov.br· Governo Federal do Brasil / CTIR Gov
- ALERTA 86/2026 — Vulnerabilidade crítica que afeta múltiplos produtos Fortinetgov.br· Governo Federal do Brasil / CTIR Gov
- Boletim do CISC de Vulnerabilidadesgov.br· Governo Federal do Brasil / CISC
- ALERTA 86/2026gov.br· Governo Federal do Brasil / CTIR Gov
- CVE-2026-93577 - CVE Recordcve.org· CVE.org
- INCIBE-CERT alerta de 11 vulnerabilidades en GitLab, dos de severidad críticamoncloa.com· Moncloa



