CVE-2026-85102CISA KEVEPSS p94.3%

CVE-2026-85102Check Point Multiple Products Improper Certificate Validation Vulnerability

Check Point / Multiple Products

Description

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.55% probability of exploitation · percentile 94.3% · 2026-10-05T12:00:23Z
Last modified2026-09-23

CISA KEV entry

Added to KEV: 2026-09-22

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.