Check Point Confirms Active CVE-2026-85102 Exploitation
The flaw affects Security Gateway and Spark Firewall, enables unauthenticated RCE, and was patched on Sept. 9.
Check Point reported active exploitation of CVE-2026-85102, a VPN certificate validation flaw that enables unauthenticated remote code execution in Security Gateway and Spark Firewall. The company said the fix had been available since Sept. 9 and that customers who applied it were already protected.
Check Point said CVE-2026-85102 is being actively exploited and released an advisory describing it as a preauthentication remote code execution flaw in the VPN certificate handling of Security Gateway. The company said the issue allows unauthenticated remote code execution during VPN negotiation, and that a fix had already been available since Sept. 9.
What vulnerability did Check Point confirm?
According to the company’s advisory, CVE-2026-85102 is caused by incorrect validation of certificate data during VPN negotiation. That flaw lets a remote, unauthenticated attacker run arbitrary code, and it carries a CVSS score of 9.8. BleepingComputer also confirmed that Check Point acknowledged active exploitation of the weakness in Security Gateway’s VPN certificate functionality.
The technical description matches other independent coverage. SecurityWeek reported that the impact includes authentication bypass and arbitrary code execution in Security Gateway, while Qualys said the vulnerability affects Security Gateway and Spark Firewall.
What scope and versions were mentioned?
The cited sources broaden the scope across multiple branches and products. AhnLab classified CVE-2026-85102 as a vulnerability in Security Gateway and Spark Firewall that can enable authentication bypass and remote code execution, and detailed remediation thresholds for R81.10, R81.20, R82, R82.10, and several Spark Firewall versions.
Security Affairs reported, citing Check Point advisories, that affected versions include both supported and unsupported branches, while R82.20 would not be affected. That same coverage noted that the available information covered products in different support states.
What did Check Point say about exploitation?
The company said a fix for CVE-2026-85102 had been available since Sept. 9 and that customers who applied it were already protected. Help Net Security added that, according to Check Point, exploitation attempts used anonymization infrastructure, including VPN services and proxies.
ENKVA attributed to Check Point that there was no evidence of exploitation when the patch was released on Sept. 9, but that a wave of attempts against Spark customers was observed starting on Sept. 12. That information was marked by the source itself as not officially confirmed.
What happened with CISA’s official response?
Secondary coverage available so far indicates that CISA added CVE-2026-85102 to its Known Exploited Vulnerabilities catalog on Sept. 22, 2026, and the reference found sets Sept. 25 as the mitigation deadline for U.S. civilian agencies. Forkast News tied that deadline to the active exploitation of the flaw already patched in September.
So far, the material reviewed does not show a specific Latin American angle. The sources do agree that exploitation was already underway, that the flaw allowed unauthenticated remote code execution, and that Check Point’s earlier patch was the mitigation already available.
Sources
- Check Point Product Security Update Advisoryasec.ahnlab.com· AhnLab ASEC
- Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616blog.checkpoint.com· Check Point Blog
- Check Point warns of hackers exploiting Security Gateway VPN RCE flawbleepingcomputer.com· BleepingComputer
- Check Point Vulnerabilities Exploited in Attacksthreatprotect.qualys.com· Qualys ThreatPROTECT
- Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instanceshelpnetsecurity.com· Help Net Security
- The VPN Certificate Bypass That Was Patched in September Is Now Actively Exploited; Federal Deadline Hits Sep. 25forkast.news· Forkast News
- Check Point Patches Exploited Management Server Zero-Daysecurityweek.com· SecurityWeek
- ENKVA #022 — Check Point's Spark VPN and management serversbuttondown.com· ENKVA
- U.S. CISA adds Check Point, Arista VeloCloud Orchestrator and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalogsecurityaffairs.com· Security Affairs



