Check Point Discloses Unauthenticated RCE Flaw in Multiple Security Products
Medium · CISA Known Exploited Vulnerabilities ·
Key points
- CVE-2026-85102 affects Check Point Security Gateway, Spark Firewall, and VPN solutions.
- Unauthenticated remote attackers can exploit a certificate validation weakness to run code.
- Organizations must apply mitigations, assess exposure, and follow BOD 26-04.
- If no fix is available, discontinue use of affected products.
Check Point has revealed a vulnerability tracked as CVE-2026-85102 that impacts several of its security offerings. The affected lineup includes Security Gateway, Spark Firewall, and both Site to Site and Remote Access VPN. An attacker who can reach these systems without credentials could leverage a certificate validation weakness to run arbitrary code. The vendor has assigned a medium severity rating, though the potential for remote code execution makes prompt action essential.
The flaw stems from improper validation of certificates, which allows an unauthenticated remote actor to bypass trust checks and execute malicious payloads. Because the impacted products are often internet-facing and central to network defense, a successful exploit could grant attackers a foothold deep inside an organization's infrastructure. This is not a targeted attack against a single customer; the issue spans multiple product lines, widening the pool of at-risk deployments.
In response, Check Point has issued mitigations and urged customers to follow Binding Operational Directive BOD 26-04. That directive likely mandates specific patching or configuration steps for federal agencies, but its guidance is relevant to any organization using these products. Administrators should first evaluate their exposure—determining which instances are reachable from untrusted networks—and then apply the recommended mitigations without delay.
If a mitigation is not available for a particular deployment, the safest course is to discontinue use of the affected product until a fix can be applied. This may mean temporarily disabling a VPN service or firewall feature, which carries operational risk but prevents exploitation. The situation remains fluid; watch for updated vendor advisories, proof-of-concept exploits, and any signs of active scanning or compromise attempts targeting CVE-2026-85102.
What to do now
- Inventory all Check Point Security Gateway, Spark Firewall, Site to Site VPN, and Remote Access VPN instances in your environment.
- Apply Check Point's official mitigations or patches for CVE-2026-85102 immediately.
- Follow BOD 26-04 requirements for federal systems; adopt equivalent measures in other environments.
- Evaluate internet exposure of affected products and restrict access where possible.
- If no mitigation exists, discontinue use of the vulnerable product until a fix is available.
- Monitor logs for exploitation attempts, unusual certificate validation errors, or unexpected code execution.
- Review and harden certificate validation configurations across all Check Point deployments.
Original source
Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.