Skip to finding
§
High
Edge — VPN
Confirmed
CVE-2026-85102

Check Point confirmed worldwide exploitation of a pre-authentication VPN certificate flaw that reaches gateway code execution.

Affects

Check Point Security Gateway and Spark Firewall, VPN and firewall appliances deployed at enterprise and small-business network edges.

What it enables

Unauthenticated code execution on a security gateway

Reach the gateway's remote-access VPN negotiation service.→↓Submit crafted certificate data that passes the defective validation path.→↓Enter the affected gateway processing context without authenticating.→↓Execute code in the gateway service context.
Why this matters

Check Point confirmed worldwide exploitation attempts against a VPN certificate-validation flaw that permits pre-authentication gateway code execution. An attacker needs network reachability to the affected remote-access VPN negotiation service and does not need to authenticate.

Detail and 2 sources
Required access

Network reachability to the affected Check Point VPN negotiation service

Affected versions

R81, R81.10, R81.10.X, R81.20, R82, R82.00.X, R82.10, R81 (end of support), R81.10 (end of support)

Proof of concept

Demonstrated by the researcher

The path requires network reachability to the affected remote-access VPN negotiation service but no authentication.

Check Point has published a fix, but pre-fix images remain accepted and complete revocation has not been established.

Evidence
Check Point identifies the primitive as pre-authentication remote code execution and confirms worldwide exploitation attempts.VulnCheck built an exploit and demonstrated the certificate-validation bypass against a live target.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 26, 2026