Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-85102: Check Point Gateways could run attacker code via VPN

CVE-2026-85102 · published 1 month ago · actively exploited
Summary

The Check Point Security Gateway and Spark Firewall that use site-to-site or remote-access VPN may not correctly check digital certificates. This allows an unauthenticated attacker to send specially crafted data and cause the gateway to run their own code. Apply the latest security updates from Check Point as soon as possible and verify the update is installed.

What to do
  • Update checkpoint gaia_os to version r81.10 or later.
Affected software
VendorProductAffected versions
checkpoint quantum security gateway R82.10 with Jumbo Hotfix Take 43 or below
check point multiple products All versions
checkpoint gaia_embedded >= r81.10.00, < r81.10.17
>= r82.00.00, < r82.00.10
r81.10.17
r82.00.10
cpe:2.3:o:checkpoint:gaia_embedded:*:*:*:*:*:*:*:*
checkpoint gaia_os >= r80, < r81.10
r81.10
r81.20
r82
r82.10
cpe:2.3:o:checkpoint:gaia_os:*:*:*:*:*:*:*:*
Original advisory text
Check Point Multiple Products Improper Certificate Validation Vulnerability
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Fix within
Internet-facing 3 days
and check for signs of compromise
Internal 3 days
and check for signs of compromise
  • Known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
8% chance of attack within 30 days
Type
CWE-295Improper Certificate Validation
Timeline
Published9 Sep 2026
Updated9 Oct 2026
First seen9 Sep 2026
Sources
CVE-2026-85102 · MITRE
CVE-2026-85102 · CISA KEV
Track software like this
Free during beta