Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Start by inventorying every potentially affected Check Point Security Gateway, Spark Firewall, and Security Management Server, then use the vendor advisory for that system’s exact release and build to select the fix. CVE-2026-85102 and CVE-2026-85103 can each allow unauthenticated remote code execution and are rated CVSS 9.8. Check Point has also reported exploitation attempts against Spark customers for CVE-2026-85102, so patching and checking for suspicious activity are separate, urgent tasks.

What do the two vulnerabilities affect?

CVE Issue Scope distinction Severity
CVE-2026-85102 Improper validation of certificate data during VPN negotiation, which can enable unauthenticated remote code execution on a Security Gateway. CERT-EU identifies deployments using Remote Access VPN or Site-to-Site VPN. Check Point later reported exploitation attempts against Spark customers. CVSS 9.8
CVE-2026-85103 Heap overflow in VPN certificate ASN.1 decoding, which can enable unauthenticated remote code execution. Includes Security Gateways and Security Management Servers; assessing gateways alone is incomplete. CVSS 9.8

The ratings are reported by CERT-EU and the Cyber Security Agency of Singapore. The configuration qualification for CVE-2026-85102 comes from CERT-EU; do not assume that the same qualification defines CVE-2026-85103’s scope.

Am I affected, and what should I inventory first?

Build a device-by-device inventory before choosing a package. CERT-EU lists Security Gateway releases R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10, R81.10.X, R81.20, R82, R82.00.X, and R82.10, and also identifies Security Management Servers plus centrally and locally managed Spark Firewalls in the affected version families. Singapore CSA explicitly identifies R82.20 as unaffected. These lists are not a substitute for checking the vendor’s current, release-specific eligibility guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For each system, record:

  • Product and role: Security Gateway, Spark Firewall, or Security Management Server.
  • Installed software release, Jumbo Hotfix Take and build, and management mode, including whether Spark is centrally or locally managed.
  • Whether Remote Access VPN or Site-to-Site VPN is configured, and whether the system is internet-facing or otherwise exposed at the perimeter.
  • Whether Check Point Live Patch is enabled and what the device currently reports about its coverage or status.

CERT-EU identifies older R80.x, R81, and R81.10 releases as End of Support. Check Check Point’s current product-lifecycle and fix-eligibility information before treating a release-family listing as proof that a particular system is supported or covered.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Which Check Point fix should I install?

  1. Match the device to the relevant vendor advisory. Use Check Point advisory sk1000117 for CVE-2026-85102 and sk1000118 for CVE-2026-85103. Select remediation using the installed product, release, build, role, and management mode—not a fix example from another branch.
  2. Check prerequisites and installation guidance for that exact branch. Follow Check Point’s package and validation instructions for the device. If eligibility, prerequisites, or safe installation are unclear, contact Check Point Support rather than guessing at a build threshold or applying a package intended for a different release.
  3. Install the applicable fix, then verify the resulting device state. Confirm the supported hotfix is installed or that applicable Live Patch coverage is active, using the version-specific vendor guidance and current Check Point tooling. Record the evidence and device/build details for each system.
  4. Repeat for every in-scope role and device. Include Security Management Servers as well as gateways and Spark Firewalls; a completed gateway rollout does not establish that management servers are remediated.

One documented example is R81.10 Jumbo Hotfix Take 190, released September 14, 2026. Its notes list fixes for both CVEs and state that each take contains all earlier takes. This example applies to R81.10; it is not a universal recommendation for other releases, products, or hardware.

Can Live Patch already protect my device?

Check Point’s initial notice said its Live Patch rollout began September 9, 2026, and that Live Patch customers would be automatically protected as the rollout began. That historical statement does not establish the current status of an individual device. Verify that the specific system is eligible and that protection is active using the applicable version-specific support advisory and current tooling. If it is not covered, or its status cannot be confirmed, follow the vendor’s instructions for the relevant Jumbo Hotfix.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

What can I do if a Site-to-Site VPN device cannot be patched immediately?

For Site-to-Site VPN deployments only, Singapore CSA relays Check Point’s interim guidance to disable implied VPN rules and restrict UDP ports 500 and 4500 to known peer IP addresses. This is a temporary risk-reduction measure while arranging the vendor fix, not proof that the vulnerability is remediated.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The advisory expressly says this mitigation does not apply to locally managed Spark Firewalls. Do not extend it to every Remote Access VPN configuration or to other deployments without vendor guidance. Confirm the change is appropriate for the specific VPN topology before applying it.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should I check for exploitation?

Check Point’s later advisory reports exploitation attempts against Spark customers beginning September 12, 2026, observed globally. This updates the vendor’s earlier notice, which said it had no evidence of exploitation at that time. The later report concerns CVE-2026-85102; the reviewed current advisory does not report exploitation for CVE-2026-85103.

  1. Review Mobile Access authentication logs. Look for anomalous certificate-based logins, including unexpected users, times, source addresses, or access patterns. Check Point says not to limit searches to the certificate subjects it has observed.
  2. Search for the observed certificate subjects. Treat matches as leads to investigate, not a complete indicator list:
    • CN=vpn,OU=users,O=global
    • CN=vpn-user,OU=users,O=global
    • CN=vpnuser,OU=users,O=global
  3. Investigate activity after suspicious logins. Check for second-stage behavior from suspicious logged-in users, including internal port and service scanning, and escalate findings through your incident-response process.

Check Point describes its indicator list as incomplete. Finding none of the listed subjects therefore does not establish that a system was not targeted. The vendor’s later exploitation advisory links to the current guidance.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

When should I escalate?

Contact Check Point Support if you cannot determine a device’s exposure, identify the correct release-specific remediation, interpret Live Patch status, or install the fix safely. Escalate suspicious logins or follow-on scanning through your organization’s incident-response process. Keep patch verification and log investigation as separate workstreams: a fix addresses exposure going forward, while it does not resolve whether suspicious activity occurred before remediation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.