
CVE-2026-85102: pre-auth RCE on your Check Point VPN gateway
CVE-2026-85102 lets an unauthenticated attacker execute code on Check Point Security Gateway and Spark firewalls via VPN certificate handling. On CISA's KEV list. What to check in 24 hours.
The short answer
CVE-2026-85102 is a pre-authentication remote code execution vulnerability in Check Point Security Gateway and Spark firewalls, CVSS v3.1 9.8, caused by improper validation of certificate data during VPN negotiation. Check Point shipped fixes on September 9, 2026 with no known exploitation; attackers started exploiting it three days later against Spark customers globally, and CISA added it to the Known Exploited Vulnerabilities catalog on September 22. If your organization runs Check Point Security Gateway or Spark for Site-to-Site or Remote Access VPN — the kind of always-on connectivity banks, fintechs, and casinos lean on for staff, contractor, and partner access — check your build and patch status today.
What CVE-2026-85102 actually is
Check Point's own advisory describes the flaw as improper validation of certificate data during VPN negotiation, allowing an unauthenticated remote attacker to execute arbitrary code on the gateway. The affected surface is Security Gateway (R81 through R82.10) and Spark firewalls, centrally or locally managed, wherever Site-to-Site VPN or Remote Access VPN is configured — the VPN negotiation path is exposed to anyone who can reach the gateway's VPN service, by design, because that's the point of a VPN endpoint. No credentials or user interaction are required.
Check Point disclosed the vulnerability and released fixes on September 9, 2026, stating there was no evidence of exploitation at that time. That changed fast: exploitation attempts began on September 12, targeting Spark firewall customers globally, using certificates with attacker-controlled subject fields designed to blend into legitimate Mobile Access logs, and routed through VPNs and proxies to obscure the attacker's real origin. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 22, 2026 — a listing that only happens after CISA has confirmed real-world exploitation — with a remediation deadline of September 25 for federal agencies.
Why a VPN gateway bug is a different category of exposure
A VPN gateway's entire job is to sit on the internet edge and accept connections from people who aren't yet trusted — that's what makes remote access work at all. It's also exactly why a pre-authentication code-execution bug on that appliance is worse than the same bug on almost anything else in the estate: there's no network segmentation, no internal-only reachability assumption, and no "but it's behind the firewall" fallback, because the VPN gateway is the firewall's front door. An attacker doesn't need to be on the internal network, doesn't need a phished credential, and doesn't need the gateway misconfigured in any unusual way — the vulnerable code path is the normal VPN negotiation flow that every legitimate remote-access session also goes through.
This is the same underlying pattern flagged twice already this year on gateways with exactly this role: CVE-2026-19490 put an unauthenticated attacker one request away from bypassing Citrix NetScaler Gateway's authentication entirely, and it's the reason network segmentation and gateway exposure sit first in the hardening priority order for a regulated payment platform rather than an afterthought — the appliances that authenticate everyone else routinely carry more privilege than almost anything they protect, and they're the least frequently pentested part of the estate precisely because "it's just the VPN box" undersells what compromising it actually gets an attacker.
What to check in the first 24 hours
- Confirm whether you run Check Point Security Gateway or Spark, and on which version. R81 through R82.10 Security Gateway builds and Spark firewalls (centrally or locally managed) are in scope wherever Site-to-Site or Remote Access VPN is configured. Don't assume — confirm the running build.
- Patch immediately, using the version-specific path. Install LivePatch Take 26 on supported gateways for the fastest remediation without a full upgrade cycle; otherwise apply the relevant Jumbo Hotfix (R81.20 Take 166, R82 Take 126, R82.10 Take 44, R81.10 Take 190 or later); for Spark firewalls, update to R82.00.10 Build 2325 or R81.10.17 Build 4968 or later. Treat this as an emergency change — CISA's KEV listing means confirmed exploitation, not a hypothetical.
- Review VPN and Mobile Access logs for anomalous certificate-based logins since September 9, 2026. Check Point's own remediation guidance specifically calls out reviewing logs for anomalous certificate-based Mobile Access activity. Look for certificate subjects that don't match your issued certificate templates, sessions with no corresponding legitimate connection attempt, and unfamiliar source IPs on VPN sessions — particularly traffic routed through commercial VPN or proxy services, which is how the observed exploitation attempts concealed their origin.
- If you can't patch today, restrict reachability as an interim measure. Limiting which source networks can reach the VPN negotiation service, where your architecture allows it, reduces exposure while the patch is scheduled — it is not a substitute for patching, and Check Point has not published it as an accepted compensating control the way some other vendors have for other CVEs.
- If you also run Check Point SmartConsole or a Security Management Server, don't assume this patch covers it. CVE-2026-85102 is a Security Gateway/Spark vulnerability; the Management Server auth bypass covered separately (CVE-2026-16232) requires its own fix and is not addressed by patching this one.
What this doesn't tell you
- A vulnerable build confirms exposure, not compromise. Being on an affected version with VPN configured means you were reachable, not that you were exploited — the log review in step 3 is what actually answers that for your environment.
- This is not exploitation guidance. Nothing here describes how the certificate-handling flaw is triggered — only how to identify exposure and detect whether it was used against you.
- Patching this specific bug doesn't audit the rest of your remote-access estate. A VPN gateway is typically one privileged entry point among several — SSO providers, other VPN concentrators, jump hosts — and this post doesn't cover auditing those.
Next step
If Check Point Security Gateway or Spark sits in front of remote access to systems that matter, patch it today and run the log review regardless of whether you believe you've been targeted — the exploitation window has been open since September 12. If you want the broader VPN and remote-access exposure reviewed rather than just this one appliance, our Security Hardening engagement scopes internet-facing gateways and admin planes for exactly this class of exposure — request a baseline review and we'll confirm what's actually reachable from the outside, not just what's theoretically in-scope by version number.
Sources and review
CVE-2026-85102's technical description (certificate-validation root cause, affected products/versions, no-authentication-required classification) and remediation paths are drawn directly from Check Point's own security advisory. The September 9 disclosure date, September 12 exploitation start, Spark-customer targeting, and the observed attacker certificate-subject pattern are corroborated by BleepingComputer's reporting. The September 22, 2026 KEV addition and September 25 remediation deadline are drawn from CISA's own Known Exploited Vulnerabilities catalog. No exploitation technique or proof-of-concept is described or referenced beyond what's needed to identify exposure. Author: AnySec Engineering. Published 2026-09-28.
Related reading
- CVE-2026-19490: auth bypass on your Citrix NetScaler gateway — the same privileged-gateway exposure pattern, a different vendor, two weeks earlier.
- CVE-2026-16232: auth bypass in Check Point console — a different Check Point product (the management console, not the gateway) with a different bug class.
- Hardening a Fintech Payment Platform: What Comes First — why network segmentation and gateway exposure lead the hardening priority order for a regulated payment platform.
- CVE-2026-20079: root access on your Cisco Firewall Management Center — a management-plane appliance compromise with fleet-wide blast radius, a different failure mode than a single gateway.
Rather not learn this in production.
Talk to the engineers behind these write-ups — no sales script, a straight read on where you stand.
Get a fixed quote
