Check Point VPN products are affected by critical vulnerabilities CVE-2026-85102 and CVE-2026-85103 that can be exploited remotely without credentials to bypass security controls and execute attacker-controlled code. CVE-2026-85102, rated CVSS 9.8, results from improper validation of certificate data during VPN negotiation in certificate-authenticated VPN functionality; exploitation against Spark Firewalls has been observed since September 12. A successful attack can fully compromise an affected gateway, expose or alter sensitive information, and disrupt services.
Affected deployments include Security Gateway and Spark Firewall Remote Access and Site-to-Site VPN configurations using certificate authentication, including DAIP and LSV setups where it may be implicitly enabled. Pre-Shared Key-only VPN configurations and version R82.20 are not affected. Check Point has released LivePatch and Jumbo Hotfix Accumulator remediation options, and the NCSC recommends immediate patching; organizations using Site-to-Site VPN should also disable implied rules and restrict VPN access to specified IP addresses.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
Check Point's advisory states that CVE-2026-85102 had been actively exploited against Spark Firewall devices since this date. The flaw can enable unauthenticated remote code execution through certificate-authenticated VPN functionality.
Check Point published advisory sk1000117 for CVE-2026-85102, a CVSS 9.8 certificate-validation flaw in Security Gateway and Spark Firewall VPN functionality. The advisory identified affected certificate-authenticated Remote Access and Site-to-Site VPN deployments and provided LivePatch, Jumbo Hotfix, and Spark Firewall build remediation options.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.