The VPN Certificate Bypass That Was Patched in September Is Now Actively Exploited — Federal Deadline Hits Sep 25
CVE-2026-85102, a critical improper certificate validation vulnerability (CWE-295) affecting the VPN negotiation flow of Check Point Security Gateways and Spark Firewalls, is now confirmed to be under active exploitation — three days before a federal compliance deadline.
The vulnerability was initially disclosed on September 9, 2026, with patches made available immediately. At the time, Check Point reported no active exploitation. That status changed within days.
Exploitation TimelineConfirmed attacks against Spark customers began on September 12. By September 14, community reports identified unauthorized VPN sessions and suspicious LDAP/LDAPS scanning originating from the VPN interface, indicating that attackers are leveraging the pre-authentication remote code execution (RCE) capability to probe internal directory services.
The vulnerability, carrying a CVSS 9.8 score, allows an unauthenticated remote attacker to execute arbitrary code on affected appliances during Remote Access VPN or Site-to-Site VPN negotiation. The issue lies in the failure to properly validate certificate trust during VPN negotiation — the appliance processes untrusted data before confirming the legitimacy of the requestor.
Federal Compliance DeadlineOn September 22, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85102 to its Known Exploited Vulnerabilities (KEV) catalog. This action triggered Binding Operational Directive (BOD) 26-04, which mandates that federal agencies remediate vulnerabilities affecting publicly exposed, automatable, total-control systems within three days. The federal compliance deadline is September 25.
Vendor ConcentrationCVE-2026-85102 was included in the same KEV batch as CVE-2026-93616, a separate zero-day affecting Check Point Security Management Servers — covered in our management server zero-day analysis. Two critical Check Point vulnerabilities in the same federal remediation batch is an unusual concentration that puts additional pressure on organizations running the vendor’s infrastructure.
A companion vulnerability, CVE-2026-85103, is a heap-based buffer overflow (CVSS 9.8) in the ASN.1 decoding flow of VPN certificates. It affects both Security Gateways and the Security Management Server. Both were patched simultaneously on September 9.
Remediation GuidanceCheck Point has provided LivePatch Take 24 for R81.20, R82, and R82.10 environments. For Spark customers, fixed builds are available: Spark R82.00.10 Build 2325 or later, and Spark R81.10.17 Build 4968 or later. Organizations running End-of-Support versions (R80 through R81.10) must upgrade to a supported release to receive patches.
Given the observed indicators of compromise — unauthorized VPN sessions and internal LDAP scanning — security teams should audit VPN logs for anomalous activity dating back to September 12. Both CERT-EU Security Advisory 2026-012 and the Dutch NCSC have issued advisories emphasizing the high likelihood of exploitation and the necessity of immediate patching.
Connections to the September ClusterThis incident sits within a broader pattern of trust infrastructure failures this beat has tracked throughout September 2026. The BlueMoon Patch-Gap showed how the gap between disclosure and patching becomes the attack surface. ADSys Trust-Store Poisoning demonstrated how a vendored script’s plaintext HTTP could compromise an enterprise trust store. The Cisco ISE Nine-CVE disclosure hit identity infrastructure at scale. The exploitation of CVE-2026-85102 extends this pattern to the VPN gateway layer — the perimeter device that secures remote enterprise access.
With over 13,000 internet-exposed Check Point VPN devices identified globally as of June 2024, the window for effective remediation is closing rapidly. Organizations that have not applied the September 9 patches are now operating in a state of active compromise risk.


Forkast News
