Check Point Security Gateway and Spark Firewall Improper Certificate Validation Vulnerability
Release Date: 22nd September 2026 (Added 23 September 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-85102 is a critical vulnerability in Check Point Security Gateway and Spark Firewall caused by a failure to properly validate certificate trust during VPN negotiation. It allows an unauthenticated remote attacker to execute code on the Security Gateway. CVSS score: 9.8 (Critical). It was disclosed alongside a companion heap-based buffer overflow in certificate decoding, CVE-2026-85103, of similar severity, which is not covered by this advisory.
What are the systems affected?
The following Check Point Security Gateway and Spark Firewall versions are affected:
- R82.10 with Jumbo Hotfix Take 43 or lower
- R82 with Jumbo Hotfix Take 125 or lower
- R81.20 with Jumbo Hotfix Take 165 or lower
Not affected / patched version:
- Devices updated via Check Point's automatic Live Patch (rollout began 9 September 2026), or updated to the latest Jumbo Hotfix Take for your deployed version, addressing CVE-2026-85102
What does this mean?
Successful exploitation may allow attackers to:
- Execute arbitrary code on the Security Gateway or Spark Firewall without any authentication, by exploiting improper certificate trust validation during VPN negotiation
- Compromise a perimeter VPN gateway, potentially exposing all traffic and remote-access sessions passing through it
- Use a compromised gateway as a foothold for further movement into the internal network it protects
Mitigation process?
CERTVU recommends the following:
-
Apply the vendor fix as an emergency change
Confirm Check Point's Live Patch has applied automatically, or manually apply the latest Jumbo Hotfix Take for your version, without delay given confirmed active exploitation. -
Apply the interim workaround if patching is delayed
Where immediate patching is not possible, disable VPN implied rules as an interim compensating control; confirm the exact configuration steps with Check Point support, as published guidance on this point has been described as non-specific. -
Treat this as top priority
Reference
- https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cve.org/CVERecord?id=CVE-2026-85102
- Download advisory (English): Check Point Security Gateway and Spark Firewall Improper Certificate Validation Vulnerability