CVE-2026-85102: 
Checkpoint CloudGuard Network Security 脆弱性の分析と軽減

概要

CVE-2026-85102 is a critical improper certificate trust validation vulnerability in Check Point Quantum Security Gateway that allows unauthenticated remote attackers to execute arbitrary code during VPN negotiation. It was disclosed and patched on September 9, 2026, with active exploitation confirmed and reported by Check Point on September 22, 2026. Affected versions include R81.20 with Jumbo Hotfix Take 165 or below, R82 with Jumbo Hotfix Take 125 or below, and R82.10 with Jumbo Hotfix Take 43 or below. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Check Point Blog, CISA KEV).

技術的な詳細

The vulnerability is classified as CWE-295 (Improper Certificate Validation) and arises from insufficient validation of certificate data during VPN negotiation in Check Point Security Gateway and Spark Firewall products. An unauthenticated remote attacker can supply a crafted certificate during the VPN handshake process — either Site-to-Site VPN or Remote Access VPN — to bypass trust checks and achieve arbitrary code execution on the gateway. No privileges or user interaction are required, and the attack is fully automatable over the network. The attack surface maps to CAPEC-459 (Creating a Rogue Certification Authority Certificate) and CAPEC-475 (Signature Spoofing by Improper Validation) (GitHub Advisory, Check Point Blog, CISA KEV).

影響

Successful exploitation grants an unauthenticated attacker full remote code execution on the Check Point Security Gateway, resulting in complete compromise of confidentiality, integrity, and availability. Because the gateway functions as a network security perimeter device, compromise enables attackers to intercept or manipulate all traffic passing through it, pivot into protected internal networks, and potentially disable security controls for downstream lateral movement. Check Point confirmed that follow-up activity after exploitation often involves internal port and service scanning, indicating use as a beachhead for broader network intrusion (Check Point Blog, CISA KEV).

エクスプロイト可能性

CVE-2026-85102 is actively exploited in the wild and was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026, with a remediation due date of September 25, 2026. Check Point confirmed a wave of exploitation attempts beginning September 12, 2026, targeting Spark customers globally, with attack traffic originating from anonymization infrastructure including VPN services and proxies. No public proof-of-concept exploit code has been identified, but the vulnerability is rated automatable with total technical impact by NVD SSVC analysis. The EPSS score is approximately 0.33%, though real-world exploitation activity significantly elevates practical risk. The vulnerability is also flagged as requiring forensic triage per CISA BOD 26-04 (Check Point Blog, CISA KEV).

エクスプロイテーションのステップ

  1. Reconnaissance: Identify internet-facing Check Point Quantum Security Gateway or Spark Firewall instances using tools like Shodan or Censys, targeting versions R81.20 ≤ Take 165, R82 ≤ Take 125, or R82.10 ≤ Take 43 with VPN (Remote Access or Site-to-Site) enabled.
  2. Craft malicious certificate: Generate a rogue X.509 certificate with a crafted subject (observed examples include CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global, CN=vpnuser,OU=users,O=global) designed to exploit the improper certificate validation logic during VPN negotiation.
  3. Initiate VPN negotiation: Send a VPN connection request to the target gateway's VPN endpoint, presenting the crafted certificate during the TLS/IKE handshake to trigger the vulnerable certificate validation code path.
  4. Achieve code execution: The gateway fails to properly validate the certificate trust chain, allowing the attacker-controlled certificate to be accepted and triggering arbitrary code execution on the gateway as a privileged process.
  5. Post-exploitation: Conduct internal network reconnaissance (port and service scanning) from the compromised gateway, leveraging its privileged network position to pivot into protected segments or intercept traffic (Check Point Blog).

妥協の兆候

  • Network: Inbound VPN negotiation attempts from anonymization infrastructure (VPN services, proxies, Tor exit nodes) to the gateway's VPN endpoint; unusual certificate subjects such as CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global, or CN=vpnuser,OU=users,O=global in VPN handshake logs.
  • Logs: Anomalous certificate-based Mobile Access login events in gateway logs; successful VPN authentications from unexpected or unrecognized certificate subjects; second-stage activity (internal port/service scans) originating from Mobile Access sessions.
  • Process/Behavior: Unexpected processes spawned by the VPN or gateway service; internal network scanning activity originating from the gateway itself post-authentication.
  • Threat Intelligence: Traffic sourced from known VPN/proxy anonymization services targeting the gateway's VPN port (Check Point Blog, CISA KEV).

軽減策と回避策

Check Point released fixes on September 9, 2026: upgrade to R81.20 with Jumbo Hotfix Take 166 or later, R82 with Jumbo Hotfix Take 126 or later, or R82.10 with Jumbo Hotfix Take 44 or later. Full remediation details, affected configurations, validation commands, and alternative mitigation steps are available in Check Point's advisory sk1000117. CISA mandates federal agencies apply mitigations by September 25, 2026 per BOD 26-04; organizations unable to patch immediately should implement network segmentation to restrict access to VPN gateway endpoints and review logs for anomalous certificate-based logins (Check Point Advisory, CISA KEV, Check Point Blog).

コミュニティの反応

Check Point issued an urgent action-required advisory on September 22, 2026, confirming active exploitation and urging immediate patching, authored by VP Research Lotem Finkelstein (Check Point Blog). Multiple national CERTs issued advisories, including Canada's CCCS (AV26-902), Ireland's NCSC, Singapore's CSA (AL-2026-121), Australia's AusCERT (ASB-2026.0222), and CERT-EU (2026-012), reflecting broad governmental concern. The Dutch NCSC warned of imminent large-scale exploitation, prompting widespread media coverage from BleepingComputer, The Hacker News, SecurityWeek, and SC World. The security community on Reddit (r/checkpoint) and Mastodon actively discussed the vulnerability, with practitioners noting this was Check Point's third critical alert in four months and highlighting the risk of VPN infrastructure as an attack surface.

関連情報


ソース: このレポートは AI を使用して生成されました

関連 Checkpoint CloudGuard Network Security 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-85102CRITICAL9.8
  • Checkpoint CloudGuard Network Security logoCheckpoint CloudGuard Network Security
  • cpe:2.3:a:checkpoint:cloudguard_network_security
はいはいSep 22, 2026
CVE-2024-24919HIGH8.6
  • Checkpoint CloudGuard Network Security logoCheckpoint CloudGuard Network Security
  • cpe:2.3:a:checkpoint:cloudguard_network_security
はいはいMay 28, 2024

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者