## Overview
CISA added CVE-2026-85102 to its Known Exploited Vulnerabilities (KEV) list on September 22, 2026. This vulnerability affects multiple Check Point products, including the Quantum Security Gateway and Spark Firewall. It involves improper certificate validation during VPN negotiation. This addition signals urgency for federal agencies to address the issue before the deadline.
## Technical Details
CVE-2026-85102 has a CVSS score of 9.8, indicating a critical severity level. The flaw allows an unauthenticated remote attacker to execute arbitrary code on the affected devices. The vulnerability arises during the VPN negotiation process, where the system fails to properly validate certificates. This oversight can lead to unauthorized access and control over the security gateway.
## Impact
Successful exploitation of this vulnerability can result in severe consequences. Attackers could gain control over the affected devices, compromising network security and data integrity. The potential for arbitrary code execution poses a significant risk to organizations relying on Check Point’s VPN solutions. The impact extends to any sensitive data transmitted through these gateways, making it a prime target for malicious actors.
## Mitigation
Organizations using affected Check Point products should prioritize patching to mitigate this vulnerability. Check Point has released updates to address CVE-2026-85102. Administrators must ensure that all systems are updated to the latest versions. Additionally, monitoring for unusual activity on VPN connections is advisable to detect any potential exploitation attempts.
CSURFACE Threat Sensor