CVE-2026-85102: Check Point Multiple Products
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
- Vendor
- Check Point
- Product
- Multiple Products
- Vulnerability
- Check Point Multiple Products Improper Certificate Validation Vulnerability
- Date added
- Sep 22, 2026
- CISA due date (U.S. federal agencies)
- Sep 25, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-295
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02