First published · Last updated
CVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability
An improper certificate validation flaw in Check Point Security Gateway and Check Point Spark Firewall used with Site-to-Site or Remote Access VPN could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. The notice requires applying vendor mitigations and following CISA’s BOD 26-04 patching and forensics triage guidance or discontinuing use if mitigations are unavailable.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 6/10
- Geographic reach
- 4/10
- Global importance
- 3/10
- Impact magnitude
- 4/10
- Positivity
- 2/10
- Urgency
- 6/10
Why it matters
The vulnerability enables unauthenticated remote execution of arbitrary code on gateway devices, and CISA directs stakeholders to mitigate or discontinue use.

