TL;DR
Security teams observed active attacks against an unpatched flaw in enterprise gateways. This critical Check Point VPN vulnerability allows unauthenticated attackers to execute arbitrary code remotely. Check Point confirmed that adversaries are actively attempting to compromise enterprise networks in the wild.
- CVE: CVE-2026-85102
- CVSS: 9.8 (Critical · CVSSv3)
- Product: checkpoint Quantum Security Gateway
- Affected: R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, R81.20 with Jumbo Hotfix Take 165 or below
- Impact: Improper Certificate Validation in Quantum Security Gateway
- Status: Exploited in the wild
- EPSS: 0.3% (30-day)
- Action: See vendor advisory
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy It Matters
This security flaw poses an urgent danger to global enterprise perimeters. Check Point released an urgent security advisory warning customers about live intrusion attempts. The vendor stated, “We are now observing exploitation attempts against Check Point Spark customers globally.” Sourced estimates indicate that tens of thousands of corporate gateways run these services worldwide. Furthermore, the vulnerability received a critical CVSS score of 9.8. Currently, researchers have observed live attacks originating from anonymized VPN proxies. However, no public proof-of-concept exploit code has been confirmed. Consequently, unpatched gateways face immediate exposure to network intrusions.
How The Attack Works
The defect targets weak certificate validation during encrypted network exchanges. The advisory states, “Improper validation of certificate data during VPN negotiation may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway.” Threat actors deliver forged digital certificates during the handshake phase. The gateway processes this malformed certificate data without verifying it properly. As a result, the flaw triggers memory corruption inside the authentication daemon. Attackers then execute arbitrary commands with administrative privileges. This attack mechanism bypasses firewall controls without requiring valid user credentials.
Affected Versions
This critical Check Point VPN vulnerability impacts Security Gateway and Spark Firewall devices running versions R81.20, R82, and R82.10. Additionally, older versions from R80 through R81.10 remain vulnerable. Conversely, systems running version R82.20 remain completely unaffected by this flaw.
Patch Or Mitigation Steps
Administrators must install Check Point LivePatch Take 26 immediately. Alternatively, teams can deploy the latest Jumbo Hotfix Accumulator updates. Full remediation details appear on the Check Point support portal. If immediate updates are not feasible, administrators should disable VPN implied rules. In addition, restrict incoming UDP traffic on ports 500 and 4500 to trusted peer addresses.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!