← nejvýznamnější zprávy · všechny zprávy

SPOJENO AI KEV ✓ (1 z 2) EPSS 0.01 (nejvyšší)

Check Point Multiple Products Improper Certificate Validation Vulnerability (CVE-2026-85102)

CISA added CVE-2026-85102 to the Known Exploited Vulnerabilities catalog. Affected product: Check Point Multiple Products. Remediation due date: 2026-09-25.

Číst originál na CISA KEV →

8 zpráv z 7 zdrojů · první 9. 9. 21:30 · poslední 23. 9. 21:53 CZ · EN/orig

Check Point US NL IT EU FR CA

tg: varování tg: zneužíváno tg: zranitelnost

CVE v události 2

CVEhodnoceníKEVEPSS
CVE-2026-85102 9.8 3.1 · checkpoint KEV ✓ 0.01
CVE-2026-85103 9.8 3.1 · checkpoint 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.

Jak se o tom psalo 8

  1. · BleepingComputer US

    Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

    Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]

  2. · CISA KEV US nadpis události

    Check Point Multiple Products Improper Certificate Validation Vulnerability (CVE-2026-85102)

    CISA added CVE-2026-85102 to the Known Exploited Vulnerabilities catalog. Affected product: Check Point Multiple Products. Remediation due date: 2026-09-25.

  3. · BleepingComputer US

    Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

    The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]

  4. · NCSC-NL NL

    NCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten

    Check Point heeft 2 kritieke kwetsbaarheden verholpen. De kwetsbaarheid met kenmerk CVE-2026-85102 heeft een CVSS-score van 9,8. De kwetsbaarheid bevindt zich in het VPN-onderhandelingsproces van de Quantum Security Gateway en wordt veroorzaakt door onjuiste validatie van certificaatvertrouwen. Hierdoor kan een niet-geauthenticeerde externe aanvaller authenticatiecontroles omzeilen en willekeurige code uitvoeren op de Security Gateway. Exploitatie vindt plaats tijdens de VPN-onderhandeling,…

  5. · CSIRT Itálie (ACN) IT

    Risolte vulnerabilità in prodotti Check Point

    Check Point ha rilasciato aggiornamenti di sicurezza che risolvono 2 vulnerabilità con gravità "critica" che interessano Security Gateway, Security Management e Spark Firewall, soluzioni dedicate alla protezione del perimetro di rete e alla gestione centralizzata della sicurezza. Le vulnerabilità potrebbero consentire ad un attaccante remoto non autenticato di eseguire codice arbitrario sui sistemi compromessi

  6. · CERT-EU EU

    2026-012: Critical Vulnerabilities in Check Point Products

    On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances. CERT-EU strongly recommends applying the available hotfixes as soon as possible,…

  7. · CERT-FR – avis FR

    Multiples vulnérabilités dans les produits Check Point (10 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans les produits Check Point. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un contournement de la politique de sécurité.

  8. · Cyber Centre Kanada CA

    Check Point security advisory (AV26-902)

    Serial Number: AV26-902Date: September 9, 2026 As of September 9, 2026, Check Point is affected by vulnerabilities in the following products: Security Gateway Multiple versions Check Point Spark Firewall using Site to Site VPN or Remote Access VPN Multiple versions Security Management Server Multiple versions Check Point Spark Firewall Multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.…