important · Edge — VPN
Check Point now reports global exploitation attempts against its pre-authentication VPN certificate RCE.
Affects
Check Point Security Gateway and Spark Firewall appliances terminating Remote Access or Site-to-Site VPN connections.
An unauthenticated client that can reach affected Remote Access or Site-to-Site negotiation can supply crafted certificate data and execute arbitrary code on the gateway.
Detail and 4 sources
Today's change is exploitation status: Check Point says the wave began September 12, and CISA added CVE-2026-85102 to KEV on September 22.
Sources
Researchhttps://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/85xxx/CVE-2026-85102.jsonVendorSecurity Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616 - Check Point BlogSecondaryCheck Point security advisory (AV26-902) – Update 2Secondaryhttps://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json