CVE-2026-85102 actively exploited: Check Point Multiple Products Improper Certificate Validation Vulnerability
CISA added CVE-2026-85102, an improper certificate validation in Check Point Multiple Products, to its Known Exploited Vulnerabilities catalogue. It could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Federal agencies must remediate by September 25, 2026.
Check Point Security Gateway and Spark Firewall devices contain an improper certificate validation flaw in their Site to Site and Remote Access VPN implementations. An unauthenticated remote attacker could leverage this weakness to execute arbitrary code on the Gateway system. The Computer Emergency Response Agency added this identifier to its catalog of known exploited vulnerabilities. Currently, no details exist regarding ransomware campaign usage for this specific flaw. Multiple Check Point products utilizing these specific VPN functionalities are at risk of remote code execution. The exposure extends to any asset where these gateways operate with the vulnerable configurations active. Organizations must evaluate each asset's internet exposure to determine if their systems match the affected profile. Federal agencies face a strict deadline to address the risk on their networks. Operators must apply mitigations strictly according to vendor instructions to resolve the breach vector. Compliance with the CISA BOD 26-04 guidance on prioritizing security updates based on risk is mandatory for federal entities. The same body requires adherence to specific forensics triage requirements during the remediation process. Federal agencies must complete these actions before the September 25 date sets in. If mitigations are unavailable, the guidance instructs users to discontinue the product usage entirely.