CISA added CVE-2026-85102 to its Known Exploited Vulnerabilities (KEV) catalogue on 22 September 2026. The vulnerability affects Check Point Security Gateway and Check Point Spark Firewall products using Site to Site VPN or Remote Access VPN. Check Point Multiple Products Improper Certificate Validation Vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
The flaw results from improper certificate validation and can be exploited remotely without authentication. Successful exploitation may enable arbitrary code execution on affected Gateway systems. The vulnerability has a CVSS score of 9.8 and is rated Critical. The available data does not confirm whether a patch is available.
Its addition to the KEV catalogue confirms active exploitation. The data does not identify use in ransomware campaigns. CISA has set 25 September 2026 as the remediation deadline, giving affected organisations a short window to assess exposure and apply the required mitigations.
CISA requires organisations to apply mitigations in accordance with vendor instructions, while following CISA’s BOD 26-04 guidance on prioritising security updates based on risk and its Forensics Triage Requirements. FCEB agencies are directly affected by this requirement. Organisations should evaluate each asset’s internet exposure and follow the applicable BOD 26-04 patching guidance; where mitigations are unavailable, they should discontinue use of the product.
See the NVD entry for CVE-2026-85102 and CISA’s KEV catalogue for full details.