
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-85102 is a critical improper certificate trust validation vulnerability in Check Point Quantum Security Gateway that allows unauthenticated remote attackers to execute arbitrary code during VPN negotiation. It was disclosed and patched on September 9, 2026, with active exploitation confirmed and reported by Check Point on September 22, 2026. Affected versions include R81.20 with Jumbo Hotfix Take 165 or below, R82 with Jumbo Hotfix Take 125 or below, and R82.10 with Jumbo Hotfix Take 43 or below. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Check Point Blog, CISA KEV).
The vulnerability is classified as CWE-295 (Improper Certificate Validation) and arises from insufficient validation of certificate data during VPN negotiation in Check Point Security Gateway and Spark Firewall products. An unauthenticated remote attacker can supply a crafted certificate during the VPN handshake process — either Site-to-Site VPN or Remote Access VPN — to bypass trust checks and achieve arbitrary code execution on the gateway. No privileges or user interaction are required, and the attack is fully automatable over the network. The attack surface maps to CAPEC-459 (Creating a Rogue Certification Authority Certificate) and CAPEC-475 (Signature Spoofing by Improper Validation) (GitHub Advisory, Check Point Blog, CISA KEV).
Successful exploitation grants an unauthenticated attacker full remote code execution on the Check Point Security Gateway, resulting in complete compromise of confidentiality, integrity, and availability. Because the gateway functions as a network security perimeter device, compromise enables attackers to intercept or manipulate all traffic passing through it, pivot into protected internal networks, and potentially disable security controls for downstream lateral movement. Check Point confirmed that follow-up activity after exploitation often involves internal port and service scanning, indicating use as a beachhead for broader network intrusion (Check Point Blog, CISA KEV).
CVE-2026-85102 is actively exploited in the wild and was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026, with a remediation due date of September 25, 2026. Check Point confirmed a wave of exploitation attempts beginning September 12, 2026, targeting Spark customers globally, with attack traffic originating from anonymization infrastructure including VPN services and proxies. No public proof-of-concept exploit code has been identified, but the vulnerability is rated automatable with total technical impact by NVD SSVC analysis. The EPSS score is approximately 0.33%, though real-world exploitation activity significantly elevates practical risk. The vulnerability is also flagged as requiring forensic triage per CISA BOD 26-04 (Check Point Blog, CISA KEV).
CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global, CN=vpnuser,OU=users,O=global) designed to exploit the improper certificate validation logic during VPN negotiation.CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global, or CN=vpnuser,OU=users,O=global in VPN handshake logs.Check Point released fixes on September 9, 2026: upgrade to R81.20 with Jumbo Hotfix Take 166 or later, R82 with Jumbo Hotfix Take 126 or later, or R82.10 with Jumbo Hotfix Take 44 or later. Full remediation details, affected configurations, validation commands, and alternative mitigation steps are available in Check Point's advisory sk1000117. CISA mandates federal agencies apply mitigations by September 25, 2026 per BOD 26-04; organizations unable to patch immediately should implement network segmentation to restrict access to VPN gateway endpoints and review logs for anomalous certificate-based logins (Check Point Advisory, CISA KEV, Check Point Blog).
Check Point issued an urgent action-required advisory on September 22, 2026, confirming active exploitation and urging immediate patching, authored by VP Research Lotem Finkelstein (Check Point Blog). Multiple national CERTs issued advisories, including Canada's CCCS (AV26-902), Ireland's NCSC, Singapore's CSA (AL-2026-121), Australia's AusCERT (ASB-2026.0222), and CERT-EU (2026-012), reflecting broad governmental concern. The Dutch NCSC warned of imminent large-scale exploitation, prompting widespread media coverage from BleepingComputer, The Hacker News, SecurityWeek, and SC World. The security community on Reddit (r/checkpoint) and Mastodon actively discussed the vulnerability, with practitioners noting this was Check Point's third critical alert in four months and highlighting the risk of VPN infrastructure as an attack surface.
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"