Junglewise Threat Intelligence

CVE-2026-85102: Check Point Security Gateway and Spark Firewall improper certificate validation in VPN

CVE-2026-85102 · Severity: critical · Exploited in the wild · Published 2026-09-22

Executive brief

Check Point security products are widely deployed to protect enterprise networks and authenticate users. An improper certificate validation flaw allows attackers to forge or bypass security certificates, potentially enabling unauthorized access to protected systems and data. CISA has confirmed this vulnerability is actively being exploited by threat actors.

Technical details

CVE-2026-85102 is an improper certificate validation vulnerability in Check Point multiple products. The vulnerability allows an attacker to bypass SSL/TLS certificate validation mechanisms, which can be exploited remotely without authentication to establish fraudulent secure connections or perform man-in-the-middle attacks. An attacker can achieve authentication bypass or intercept encrypted communications, gaining unauthorized access to protected resources. This vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog indicating active exploitation. Patches or mitigations should be prioritized based on CISA's BOD 26-04 guidance for federal agencies.

Affected products

  • Check Point Multiple Products

Timeline

  • 2026-09-22: kev added

References

Related threats