CVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability

Summary

A vulnerability, CVE-2026-85102, has been identified in Check Point Security Gateway and Check Point Spark Firewall products. This improper certificate validation flaw could permit an unauthenticated remote attacker to execute arbitrary code on the gateway.

IFF Assessment

FOE

This vulnerability allows for arbitrary code execution, posing a significant risk to targeted systems and networks.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 25, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in Check Point products, particularly those involved in VPN, presents a critical risk. Defenders must prioritize applying vendor-provided mitigations and adhere to CISA's directives regarding security updates. The potential for unauthenticated remote code execution necessitates immediate attention to patch or mitigate these systems.

Read Full Story →