[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"news-aggregator-the-vpn-certificate-bypass-tha4701a0ce91-0379-7e21-84b3-341aab024eba":3},{"id":4,"timestamp":5,"title":6,"content":7,"link":8,"preview":9,"tags":10,"predictedTags":11,"showTags":12,"source":13,"reactions":14,"selfReactions":15,"logo":16,"sourceId":17,"sourceUserId":18,"asset":19,"tagsCategories":20,"totalComments":21,"lang":22,"unique_views_count":21,"enrichStatus":23,"triageKind":18,"triageImportance":18,"expandEligible":18,"summarizeEligible":18,"eventEligible":18,"eventType":18,"eventAction":18},"the-vpn-certificate-bypass-tha4701a0ce91-0379-7e21-84b3-341aab024eba","1790171105000","The VPN Certificate Bypass That Was Patched in September Is Now Actively Exploited — Federal Deadline Hits Sep 25","\u003Cp>CVE-2026-85102, a critical improper certificate validation vulnerability (CWE-295) affecting the VPN negotiation flow of Check Point Security Gateways and Spark Firewalls, is now confirmed to be under active exploitation — three days before a federal compliance deadline.\u003C/p>\u003Cp>The vulnerability was initially disclosed on September 9, 2026, with patches made available immediately. At the time, Check Point reported no active exploitation. That status changed within days.\u003C/p>Exploitation Timeline\u003Cp>Confirmed attacks against Spark customers began on September 12. By September 14, community reports identified unauthorized VPN sessions and suspicious LDAP/LDAPS scanning originating from the VPN interface, indicating that attackers are leveraging the pre-authentication remote code execution (RCE) capability to probe internal directory services.\u003C/p>\u003Cp>The vulnerability, carrying a CVSS 9.8 score, allows an unauthenticated remote attacker to execute arbitrary code on affected appliances during Remote Access VPN or Site-to-Site VPN negotiation. The issue lies in the failure to properly validate certificate trust during VPN negotiation — the appliance processes untrusted data before confirming the legitimacy of the requestor.\u003C/p>Federal Compliance Deadline\u003Cp>On September 22, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85102 to its \u003Ca href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\" target=\"_blank\">Known Exploited Vulnerabilities (KEV) catalog\u003C/a>. This action triggered Binding Operational Directive (BOD) 26-04, which mandates that federal agencies remediate vulnerabilities affecting publicly exposed, automatable, total-control systems within three days. The federal compliance deadline is September 25.\u003C/p>Vendor Concentration\u003Cp>CVE-2026-85102 was included in the same KEV batch as CVE-2026-93616, a separate zero-day affecting Check Point Security Management Servers — covered in our \u003Ca href=\"/the-control-tower-left-unguarded-check-points-management-server-zero-day-gave-attackers-two-months-of-silent-access/\">management server zero-day analysis\u003C/a>. Two critical Check Point vulnerabilities in the same federal remediation batch is an unusual concentration that puts additional pressure on organizations running the vendor’s infrastructure.\u003C/p>\u003Cp>A companion vulnerability, CVE-2026-85103, is a heap-based buffer overflow (CVSS 9.8) in the ASN.1 decoding flow of VPN certificates. It affects both Security Gateways and the Security Management Server. Both were patched simultaneously on September 9.\u003C/p>Remediation Guidance\u003Cp>Check Point has provided LivePatch Take 24 for R81.20, R82, and R82.10 environments. For Spark customers, fixed builds are available: Spark R82.00.10 Build 2325 or later, and Spark R81.10.17 Build 4968 or later. Organizations running End-of-Support versions (R80 through R81.10) must upgrade to a supported release to receive patches.\u003C/p>\u003Cp>Given the observed indicators of compromise — unauthorized VPN sessions and internal LDAP scanning — security teams should audit VPN logs for anomalous activity dating back to September 12. Both \u003Ca href=\"https://cert.europa.eu/publications/security-advisories/2026-012/\" target=\"_blank\">CERT-EU Security Advisory 2026-012\u003C/a> and the Dutch NCSC have issued advisories emphasizing the high likelihood of exploitation and the necessity of immediate patching.\u003C/p>Connections to the September Cluster\u003Cp>This incident sits within a broader pattern of trust infrastructure failures this beat has tracked throughout September 2026. The \u003Ca href=\"/the-patch-gap-is-the-attack-surface-bluemoon-exploit-kit-arms-five-chinese-apts-in-12-days/\">BlueMoon Patch-Gap\u003C/a> showed how the gap between disclosure and patching becomes the attack surface. \u003Ca href=\"/one-http-request-full-trust-poisoning-adsyss-certificate-enrollment-flaw/\">ADSys Trust-Store Poisoning\u003C/a> demonstrated how a vendored script’s plaintext HTTP could compromise an enterprise trust store. The \u003Ca href=\"/the-gatekeeper-is-the-door-cisco-ises-nine-cve-disclosure-and-the-identity-infrastructure-attack-surface/\">Cisco ISE Nine-CVE\u003C/a> disclosure hit identity infrastructure at scale. The exploitation of CVE-2026-85102 extends this pattern to the VPN gateway layer — the perimeter device that secures remote enterprise access.\u003C/p>\u003Cp>With over 13,000 internet-exposed Check Point VPN devices identified globally as of June 2024, the window for effective remediation is closing rapidly. Organizations that have not applied the September 9 patches are now operating in a state of active compromise risk.\u003C/p>","https://forkast.news/the-vpn-certificate-bypass-that-was-patched-in-september-is-now-actively-exploited-federal-deadline-hits-sep-25/","https://forkast.news/wp-content/uploads/2026/09/check-point-vpn-cve-2026-85102-hero-1024x572.jpg","[\"Trust & Security\"]","[\"Flow\",\"FLOW\",\"Spark\"]","[{\"img\":\"https://toscalepublic.s3.eu-west-2.amazonaws.com/images/coins-lib/full-library/color/FLOW.png\",\"name\":\"FLOW\"},{\"name\":\"Spark\",\"logo\":\"https://toscalepublic.s3.eu-west-2.amazonaws.com/images/protocols/spark.png\"}]","47",[],[],"https://toscalepublic.s3.eu-west-2.amazonaws.com/images/news-feeds/sources/forkast-news.png","Forkast News",null,"","[\"Crypto\"]","0","EN","done"]