Cyber & AI intelligence
Wasteland.
Briefs indexed2807
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-85102 2026-09-22

Check Point Gateways Under Active Attack: CVE-2026-85102 Hits KEV with a 3-Day Deadline

"CISA added CVE-2026-85102, an improper certificate validation flaw in Check Point VPN gateways, which the vendor describes as enabling unauthenticated remote code execution and rates critical (CVSS 9.8), to the Known…"

CISA added CVE-2026-85102, an improper certificate validation flaw in Check Point VPN gateways, which the vendor describes as enabling unauthenticated remote code execution and rates critical (CVSS 9.8), to the Known Exploited Vulnerabilities catalog on 2026-09-22, with a remediation due date of 2026-09-25.

What Is It

CVE-2026-85102 is an improper certificate trust validation weakness (CWE-295) that occurs during VPN negotiation on Check Point Quantum Security Gateway. Check Point's record pairs that root-cause classification with an impact of unauthenticated remote code execution on the gateway itself. The vendor has not published the intermediate steps that connect the certificate-trust failure to code execution, and no public technical analysis of the exploitation chain is available, so the relationship between the two should be read as the vendor's characterization of the same defect rather than a documented mechanism.

The CVE was published 2026-09-09 by Check Point, which as the assigning CNA supplied the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and a base score of 9.8 CRITICAL: no privileges, no user interaction, low attack complexity, network-reachable, and total impact across confidentiality, integrity, and availability. The record remains in "Awaiting Analysis" status at NVD, so those values are the vendor's assessment and have not yet been independently confirmed or adjusted by NVD analysts.

Why It Matters

CISA's KEV listing confirms active exploitation in the wild. The accompanying SSVC decision points are recorded as exploitation active, automatable yes, and technical impact total.

The affected component is a VPN-terminating security gateway; by design an internet-facing device sitting at the network perimeter with visibility into internal traffic. Code execution on that box is code execution at the trust boundary. CISA has also flagged this entry as requiring forensic triage, meaning patching alone is not the assumed end state; affected organizations are expected to look for evidence of compromise.

The 3-day window between KEV addition (2026-09-22) and due date (2026-09-25) is unusually short and reflects the urgency.

What's Vulnerable

Per Check Point's CVE record, affected Quantum Security Gateway versions are:

CISA's KEV entry describes the affected scope as Check Point Security Gateway and Check Point Spark Firewall using Site-to-Site VPN or Remote Access VPN.

Patch Status

Check Point has published guidance in sk1000117. CISA's required action is to apply mitigations per vendor instructions in compliance with BOD 26-04 ("Prioritizing Security Updates Based on Risk") and CISA's Forensics Triage Requirements. Where mitigations are unavailable, CISA directs organizations to follow applicable BOD 26-04 cloud-service guidance or discontinue use of the product. Asset owners are responsible for evaluating each asset's internet exposure.

Known ransomware campaign use is listed as Unknown.

Sources