Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-85102: Check Point Gateways could run attacker code via VPN
CVE-2026-85102 · published 1 month ago · actively exploited
Summary
The Check Point Security Gateway and Spark Firewall that use site-to-site or remote-access VPN may not correctly check digital certificates. This allows an unauthenticated attacker to send specially crafted data and cause the gateway to run their own code. Apply the latest security updates from Check Point as soon as possible and verify the update is installed.
What to do
- Update checkpoint gaia_os to version r81.10 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| checkpoint | quantum security gateway | R82.10 with Jumbo Hotfix Take 43 or below |
| check point | multiple products | All versions |
| checkpoint | gaia_embedded |
>= r81.10.00, < r81.10.17 >= r82.00.00, < r82.00.10 r81.10.17 r82.00.10 cpe:2.3:o:checkpoint:gaia_embedded:*:*:*:*:*:*:*:* |
| checkpoint | gaia_os |
>= r80, < r81.10 r81.10 r81.20 r82 r82.10 cpe:2.3:o:checkpoint:gaia_os:*:*:*:*:*:*:*:* |
Original advisory text
Check Point Multiple Products Improper Certificate Validation Vulnerability
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
References
- https://blog.checkpoint.com/security/security-advisory-action-required-active-ex... Vendor Advisory
- https://support.checkpoint.com/results/sk/sk1000117 Mitigation Patch Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-... US Government Resource
Internet-facing
3 days
and check for signs of compromise
Internal
3 days
and check for signs of compromise
- Known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
8%
chance of attack within 30 days
Type
CWE-295Improper Certificate Validation
Timeline
Published9 Sep 2026
Updated9 Oct 2026
First seen9 Sep 2026
Track software like this
Free during beta