Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN889 _____________________________________________________________________ DATE : 15/09/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Security Gateway, Check Point Spark Firewall using Site to Site VPN or Remote Access VPN. ===================================================================== https://support.checkpoint.com/results/sk/sk1000117/ _____________________________________________________________________ CVE-2026-85102 - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN Please read this important update from Check Point. Security Alert: Critical Product Security Gateway, Spark Firewall (Centrally Managed), Spark Firewall (Locally Managed) Version R81 (EOS), R81.10 (EOS), R81.10.X, R81.10.X, R81.20, R82, R82.00.X, R82.00.X, R82.10 Last Modified2026-09-09 Symptoms Issue: Improper validation of certificate data during VPN negotiation may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway. This issue received the ID CVE-2026-85102 with CVSS: 9.8. Affected Products: Security Gateway, Check Point Spark Firewall using Site to Site VPN or Remote Access VPN Affected Versions: R81.20, R82, R82.10 R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10 (all EoS) R81.10.x, R82.00.x Not Affected Versions: R82.20 Mitigation For Site to Site VPN, disable implied rules for VPN and manually define VPN access for UDP/500 and UDP/4500 for the specific peer IP addresses. Note: This mitigation option is not applicable to the locally managed Spark Firewall. Solution This problem was fixed. Option 1: The fix is included in Check Point LivePatch Automatic installation If you have enabled automatic installation of Check Point LivePatch, the protection will be applied automatically. Manual installation Download the offline package from the table below: Version Take Number Download Package R82.10 BUNDLE_URGENT_SECURITY_UPDATE_R82_10_AUTOUPDATE take 24 (TAR) R82 BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE take 24 (TAR) R81.20 BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE take 24 (TAR) To validate that LivePatch is properly installed and active, run the cpinfo -y CPupdates command on the Security Gateway / ClusterXL member in Expert mode and validate that you have BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE Take 24 Example: [Expert@Host:0]# cpinfo -y CPupdates [CPUpdates]   BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE  Take: 24 For LivePatch validation, run in Expert mode: On a Security Gateway / ClusterXL member: cplp list On a Scalable Platform Security Group: g_all cplp list Expected output: cpcert:cpca* CVE-2026-85102 CVE-2026-85103 cpcert:iked* CVE-2026-85102 CVE-2026-85103 cpcert:vpn* CVE-2026-85102 CVE-2026-85103 cpcert:vpnrad* CVE-2026-85102 CVE-2026-85103 cpcert:wstlsd* CVE-2026-85102 CVE-2026-85103 cpcert_cprid:cprid* CVE-2026-85102 CVE-2026-85103 Option 2: The fix is also included in: Jumbo Hotfix Accumulator for R82.10 starting from Take 44 Jumbo Hotfix Accumulator for R82 starting from Take 126 Jumbo Hotfix Accumulator for R81.20 starting from Take 166 Check Point Spark Firewalls R82.00.10 starting from Build 2325 Check Point Spark Firewalls R81.10.17 starting from Build 4968 Article Properties Access Level General Severity CRITICAL Status Approved Date Created 2026-09-07 Last Modified 2026-09-09 ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================