A significant security flaw has been identified in Check Point products that utilizes VPN functionality. Organizations using these networking solutions should review their infrastructure and apply available vendor updates promptly.
According to official advisories, the issue affects Check Point Security Gateway and Check Point Spark Firewall systems using Site-to-Site VPN or Remote Access VPN configurations. Because this security advisory is actively monitored and tracked, site owners and IT administrators need to understand the potential risks and required remediation steps.
What Happened
The vulnerability, officially tracked as CVE-2026-85102, involves improper certificate validation within specific Check Point products. This flaw could allow an unauthenticated remote attacker to execute arbitrary code on the affected Gateway.
Crucially, this issue has been documented on CISA's Known Exploited Vulnerabilities list, indicating that active exploitation attempts have been observed in the wild. This designation elevates the urgency for organizations running the affected software to take immediate protective action.
Who Should Care
Small businesses, enterprise environments, and IT service providers utilizing Check Point Security Gateways or Spark Firewalls with active VPN tunnels must pay close attention to this advisory. If your perimeter security relies on these products for remote workforce access or branch office connections, your infrastructure is exposed until updated.
Even smaller organizations that rely on managed service providers for firewall administration should verify that their external-facing gateways have been properly secured against this vulnerability.
What to Do Now
Protecting your network infrastructure requires a structured and immediate response:
- Inventory your assets: Confirm whether your organization utilizes Check Point Security Gateway or Spark Firewall products with VPN features enabled.
- Apply vendor guidance: Check the official Check Point advisory channels for the latest security updates and configuration recommendations.
- Monitor perimeter logs: Review firewall and VPN access logs for any unusual or unauthorized connection attempts.
- Scan your perimeter: Regularly audit your external-facing systems for known vulnerabilities.
Run a free check on your external perimeter at Korisec to identify potential exposure points across your web assets and digital infrastructure.