Skip to content
CC-4849

CC-4849

Digital.Nhs.Uk •[email protected] (NHS Digital) • September 10, 2026

Successful exploitation of CVE-2026-85102 could allow an unauthenticated remote attacker to execute arbitrary code on a vulnerable gateway, potentially leading to complete compromise of the affected device

Successful exploitation of CVE-2026-85102 could allow an unauthenticated remote attacker to execute arbitrary code on a vulnerable gateway, potentially leading to complete compromise of the affected device

The following platforms are known to be affected:

Check Point Remote Access VPN

All versions of Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN:

R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10 (all End of Support)

Note: The vulnerability affects both centrally and locally managed Spark Firewall.

Check Point has released a security advisory to address a critical vulnerability in their Security Gateway platform. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on a vulnerable gateway, potentially leading to complete compromise of the affected device.

CVE-2026-85102 – Improper Certificate Trust Validation vulnerability – CVSS v3.1 score: 9.8

Affected organisations are encouraged to review Check Point Security Advisory SK1000117 and apply the relevant update as soon as possible. Organisations using Check Point LivePatch should verify that the latest protections have been successfully applied.

Definitive source of threat updates

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Last edited: 10 September 2026 2:59 pm