CVE-2026-85102: 
Checkpoint CloudGuard Network Security Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-85102 is a critical improper certificate trust validation vulnerability in Check Point Quantum Security Gateway that allows unauthenticated remote attackers to execute arbitrary code during VPN negotiation. It was disclosed and patched on September 9, 2026, with active exploitation confirmed and reported by Check Point on September 22, 2026. Affected versions include R81.20 with Jumbo Hotfix Take 165 or below, R82 with Jumbo Hotfix Take 125 or below, and R82.10 with Jumbo Hotfix Take 43 or below. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Check Point Blog, CISA KEV).

Détails techniques

The vulnerability is classified as CWE-295 (Improper Certificate Validation) and arises from insufficient validation of certificate data during VPN negotiation in Check Point Security Gateway and Spark Firewall products. An unauthenticated remote attacker can supply a crafted certificate during the VPN handshake process — either Site-to-Site VPN or Remote Access VPN — to bypass trust checks and achieve arbitrary code execution on the gateway. No privileges or user interaction are required, and the attack is fully automatable over the network. The attack surface maps to CAPEC-459 (Creating a Rogue Certification Authority Certificate) and CAPEC-475 (Signature Spoofing by Improper Validation) (GitHub Advisory, Check Point Blog, CISA KEV).

Impact

Successful exploitation grants an unauthenticated attacker full remote code execution on the Check Point Security Gateway, resulting in complete compromise of confidentiality, integrity, and availability. Because the gateway functions as a network security perimeter device, compromise enables attackers to intercept or manipulate all traffic passing through it, pivot into protected internal networks, and potentially disable security controls for downstream lateral movement. Check Point confirmed that follow-up activity after exploitation often involves internal port and service scanning, indicating use as a beachhead for broader network intrusion (Check Point Blog, CISA KEV).

Exploitabilité

CVE-2026-85102 is actively exploited in the wild and was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026, with a remediation due date of September 25, 2026. Check Point confirmed a wave of exploitation attempts beginning September 12, 2026, targeting Spark customers globally, with attack traffic originating from anonymization infrastructure including VPN services and proxies. No public proof-of-concept exploit code has been identified, but the vulnerability is rated automatable with total technical impact by NVD SSVC analysis. The EPSS score is approximately 0.33%, though real-world exploitation activity significantly elevates practical risk. The vulnerability is also flagged as requiring forensic triage per CISA BOD 26-04 (Check Point Blog, CISA KEV).

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing Check Point Quantum Security Gateway or Spark Firewall instances using tools like Shodan or Censys, targeting versions R81.20 ≤ Take 165, R82 ≤ Take 125, or R82.10 ≤ Take 43 with VPN (Remote Access or Site-to-Site) enabled.
  2. Craft malicious certificate: Generate a rogue X.509 certificate with a crafted subject (observed examples include CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global, CN=vpnuser,OU=users,O=global) designed to exploit the improper certificate validation logic during VPN negotiation.
  3. Initiate VPN negotiation: Send a VPN connection request to the target gateway's VPN endpoint, presenting the crafted certificate during the TLS/IKE handshake to trigger the vulnerable certificate validation code path.
  4. Achieve code execution: The gateway fails to properly validate the certificate trust chain, allowing the attacker-controlled certificate to be accepted and triggering arbitrary code execution on the gateway as a privileged process.
  5. Post-exploitation: Conduct internal network reconnaissance (port and service scanning) from the compromised gateway, leveraging its privileged network position to pivot into protected segments or intercept traffic (Check Point Blog).

Indicateurs de compromis

  • Network: Inbound VPN negotiation attempts from anonymization infrastructure (VPN services, proxies, Tor exit nodes) to the gateway's VPN endpoint; unusual certificate subjects such as CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global, or CN=vpnuser,OU=users,O=global in VPN handshake logs.
  • Logs: Anomalous certificate-based Mobile Access login events in gateway logs; successful VPN authentications from unexpected or unrecognized certificate subjects; second-stage activity (internal port/service scans) originating from Mobile Access sessions.
  • Process/Behavior: Unexpected processes spawned by the VPN or gateway service; internal network scanning activity originating from the gateway itself post-authentication.
  • Threat Intelligence: Traffic sourced from known VPN/proxy anonymization services targeting the gateway's VPN port (Check Point Blog, CISA KEV).

Atténuation et solutions de contournement

Check Point released fixes on September 9, 2026: upgrade to R81.20 with Jumbo Hotfix Take 166 or later, R82 with Jumbo Hotfix Take 126 or later, or R82.10 with Jumbo Hotfix Take 44 or later. Full remediation details, affected configurations, validation commands, and alternative mitigation steps are available in Check Point's advisory sk1000117. CISA mandates federal agencies apply mitigations by September 25, 2026 per BOD 26-04; organizations unable to patch immediately should implement network segmentation to restrict access to VPN gateway endpoints and review logs for anomalous certificate-based logins (Check Point Advisory, CISA KEV, Check Point Blog).

Réactions de la communauté

Check Point issued an urgent action-required advisory on September 22, 2026, confirming active exploitation and urging immediate patching, authored by VP Research Lotem Finkelstein (Check Point Blog). Multiple national CERTs issued advisories, including Canada's CCCS (AV26-902), Ireland's NCSC, Singapore's CSA (AL-2026-121), Australia's AusCERT (ASB-2026.0222), and CERT-EU (2026-012), reflecting broad governmental concern. The Dutch NCSC warned of imminent large-scale exploitation, prompting widespread media coverage from BleepingComputer, The Hacker News, SecurityWeek, and SC World. The security community on Reddit (r/checkpoint) and Mastodon actively discussed the vulnerability, with practitioners noting this was Check Point's third critical alert in four months and highlighting the risk of VPN infrastructure as an attack surface.

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Checkpoint CloudGuard Network Security Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-85102CRITICAL9.8
  • Checkpoint CloudGuard Network Security logoCheckpoint CloudGuard Network Security
  • cpe:2.3:a:checkpoint:cloudguard_network_security
OuiOuiSep 22, 2026
CVE-2024-24919HIGH8.6
  • Checkpoint CloudGuard Network Security logoCheckpoint CloudGuard Network Security
  • cpe:2.3:a:checkpoint:cloudguard_network_security
OuiOuiMay 28, 2024

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités