SPOJENO AI KEV ✓ (1 z 2) EPSS 0.01 (nejvyšší)
Check Point Multiple Products Improper Certificate Validation Vulnerability (CVE-2026-85102)
CISA added CVE-2026-85102 to the Known Exploited Vulnerabilities catalog. Affected product: Check Point Multiple Products. Remediation due date: 2026-09-25.
Check Point US NL IT EU FR CA
CVE v události 2
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-85102 | 9.8 3.1 · checkpoint | KEV ✓ | 0.01 |
| CVE-2026-85103 | 9.8 3.1 · checkpoint | – | 0.00 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.
Jak se o tom psalo 8
-
· BleepingComputer US
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]
-
· CISA KEV US nadpis události
Check Point Multiple Products Improper Certificate Validation Vulnerability (CVE-2026-85102)
CISA added CVE-2026-85102 to the Known Exploited Vulnerabilities catalog. Affected product: Check Point Multiple Products. Remediation due date: 2026-09-25.
-
· BleepingComputer US
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]
-
· NCSC-NL NL
NCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten
Check Point heeft 2 kritieke kwetsbaarheden verholpen. De kwetsbaarheid met kenmerk CVE-2026-85102 heeft een CVSS-score van 9,8. De kwetsbaarheid bevindt zich in het VPN-onderhandelingsproces van de Quantum Security Gateway en wordt veroorzaakt door onjuiste validatie van certificaatvertrouwen. Hierdoor kan een niet-geauthenticeerde externe aanvaller authenticatiecontroles omzeilen en willekeurige code uitvoeren op de Security Gateway. Exploitatie vindt plaats tijdens de VPN-onderhandeling,…
-
· CSIRT Itálie (ACN) IT
Risolte vulnerabilità in prodotti Check Point
Check Point ha rilasciato aggiornamenti di sicurezza che risolvono 2 vulnerabilità con gravità "critica" che interessano Security Gateway, Security Management e Spark Firewall, soluzioni dedicate alla protezione del perimetro di rete e alla gestione centralizzata della sicurezza. Le vulnerabilità potrebbero consentire ad un attaccante remoto non autenticato di eseguire codice arbitrario sui sistemi compromessi
-
· CERT-EU EU
2026-012: Critical Vulnerabilities in Check Point Products
On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances. CERT-EU strongly recommends applying the available hotfixes as soon as possible,…
-
· CERT-FR – avis FR
Multiples vulnérabilités dans les produits Check Point (10 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits Check Point. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un contournement de la politique de sécurité.
-
· Cyber Centre Kanada CA
Check Point security advisory (AV26-902)
Serial Number: AV26-902Date: September 9, 2026 As of September 9, 2026, Check Point is affected by vulnerabilities in the following products: Security Gateway Multiple versions Check Point Spark Firewall using Site to Site VPN or Remote Access VPN Multiple versions Security Management Server Multiple versions Check Point Spark Firewall Multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.…