CISA Adds Critical Check Point VPN Flaw to Actively Exploited Vulnerabilities

CISA has added CVE-2026-85102 in Check Point devices to its Known Exploited Vulnerabilities catalog. The vendor recommends immediately deploying the hotfix available since September 9.

The CVE-2026-85102 Check Point VPN vulnerability was added to the U.S. agency CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026. It is a critical flaw in the VPN components of Check Point security devices, with the vendor confirming active exploitation attempts against customers using the Spark product line.

According to its security advisory, Check Point has observed these attempts since September 12. A fix has been available since September 9, and the vendor recommends that affected organizations immediately deploy the relevant hotfix.

CVE-2026-85102 Check Point VPN flaw enables unauthenticated attacks

The flaw has the identifier CVE-2026-85102 and a CVSS score of 9.8 out of 10. It is a pre-authentication remote code execution (RCE) vulnerability. It occurs during certificate processing while establishing a VPN connection.

As a result, an attacker does not need valid login credentials when the vulnerable configuration is accessible. Successful exploitation may allow arbitrary code to be executed directly on the device.

The affected products are Security Gateway and Check Point Spark Firewall when configured for Site-to-Site VPN or Remote Access VPN. Organizations should therefore verify whether these VPN modes are deployed, check the version in use, and apply the hotfix specified by the vendor.

CISA lists the flaw in its KEV catalog

Being added to the KEV catalog means that CISA considers the vulnerability a flaw with known exploitation in the wild. For the CVE-2026-85102 entry, the agency recommends following the vendor’s instructions.

In its advisory, Check Point lists the hotfix under the designation sk1000117. In addition to updating, administrators should review VPN access logs and look for suspicious activity related to certificate-based VPN negotiation.

Scope of compromises has not yet been confirmed

It has not been publicly confirmed how many organizations may have been compromised or who is behind the attacks. Check Point reported observed exploitation attempts but did not publish complete technical details of the attack chain.

Further information may come from updates by Check Point and CISA, or from the publication of indicators of compromise or attribution of the activity to a specific group. Until then, the priority is deploying the available fix on internet-facing VPN gateways in the affected configurations.

Sources

  • Check Point Blog – The vendor confirms active exploitation of CVE-2026-85102, the affected products, severity, and the availability of a fix since September 9, 2026.
  • CISA Known Exploited Vulnerabilities Catalog – CISA lists CVE-2026-85102 in the KEV catalog and states that users should follow the vendor’s instructions.
  • Canadian Centre for Cyber Security – Canada’s national cyber center independently states that Check Point reported exploitation of CVE-2026-85102 in the wild.

Verified and updated: September 23, 2026 06:22

Sharing