Status: KEV | Advisory ID: CVE-2026-85102
| CVE | CVE-2026-85102 |
| Affected products | Check Point Multiple Products |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-295 (Improper Certificate Validation) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-22. |
| Federal remediation deadline | 2026-09-25 (CISA KEV, Binding Operational Directive). |
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-85102 |