ZeroDayAlert

CVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Check Point Multiple Products Added to KEV 2026-09-22 Federal due 2026-09-25 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Check Point Security Gateway and Check Point Spark Firewall are vulnerable when configured to use Site to Site VPN or Remote Access VPN. An unauthenticated remote attacker can exploit improper certificate validation to execute arbitrary code. The record does not specify affected versions, patch availability, or whether on-premises and cloud deployments are equally exposed.

How to check whether this touches you

  • Inventory all Check Point Security Gateway and Spark Firewall instances in your environment and note their deployment type (on-premises, cloud, hybrid).
  • For each instance, confirm whether Site to Site VPN or Remote Access VPN is enabled in the configuration.
  • Establish whether each affected instance is reachable from the internet or from untrusted networks; check firewall rules, network segmentation, and any reverse proxies or load balancers in front of it.
  • Query the running version via the management console or SSH access to the appliance; compare against Check Point's advisory for affected and patched versions.
  • Check logs for any unusual certificate validation errors, failed authentication attempts, or unexpected connections to the VPN endpoints.

What to do

  1. Review Check Point's published advisory for this CVE to identify which versions are affected and what patches or mitigations are available.
  2. If you cannot patch immediately, disable Site to Site VPN and Remote Access VPN on affected instances if business operations permit; otherwise, restrict VPN endpoint access to known, trusted IP ranges via firewall rules.
  3. Enable detailed logging of all VPN authentication attempts and certificate validation events; ship logs to a centralised, immutable store.
  4. Schedule patching in accordance with CISA BOD 26-04 guidance (which prioritises internet-facing critical infrastructure); treat this as a high-priority change because unauthenticated remote code execution requires no prior access.
  5. If patches are unavailable and you cannot disable or isolate the service, escalate to Check Point support and your information security leadership to evaluate whether continued use is acceptable under your risk policy.

If you find you were exposed

Exploitation of improper certificate validation typically occurs before public disclosure; the record does not specify when active use began. Search your VPN authentication logs, firewall access logs, and system event logs for anomalous connections, failed certificate checks, or command execution around the time the vulnerability became known in your supply chain. Log retention is usually the limiting factor—work backwards from today and retrieve as much history as your systems retain.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-85102 is being exploited. It cannot tell you whether Multiple Products is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →