Check Point Security Gateway and Spark Firewall Improper Certificate Validation Vulnerability

Release Date: 22nd September 2026 (Added 23 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-85102 is a critical vulnerability in Check Point Security Gateway and Spark Firewall caused by a failure to properly validate certificate trust during VPN negotiation. It allows an unauthenticated remote attacker to execute code on the Security Gateway. CVSS score: 9.8 (Critical). It was disclosed alongside a companion heap-based buffer overflow in certificate decoding, CVE-2026-85103, of similar severity, which is not covered by this advisory.

Reference

  1. https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://www.cve.org/CVERecord?id=CVE-2026-85102