The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Public sources reviewed for these vulnerabilities do not establish how many Check Point systems remain exposed. Check Point has reported exploitation attempts against Spark customers, but that observation is not an internet-wide host count. The two CVEs affect different code paths and product roles, so a product banner alone cannot confirm that a device is vulnerable.
What internet scanning can—and cannot—tell you
A scan can identify internet-visible services or product characteristics, but that is not the same as verifying a vulnerable installation. A banner or other fingerprint does not, by itself, establish the appliance’s exact software build, installed Jumbo Hotfix, or VPN configuration. Those details matter to whether a particular system falls within a vulnerability’s affected scope.
The Shodan CVE dashboard page reviewed for these flaws presented vulnerability and product information, but no clearly attributable asset count or scan methodology. Check Point’s and CERT-EU’s advisories describe affected software and security activity; neither supplies a census of internet-facing devices. No reproducible public internet-wide exposure count was established in the sources reviewed here.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →A defensible exposure estimate would need to state when the scan ran, how it identified devices, whether it counted raw fingerprints or verified vulnerable builds, how duplicates were handled, and what networks or regions it covered. Without those details, a number could be mistaken for a count of confirmed vulnerable systems when it may only reflect devices that a particular scan could see.
How the two vulnerabilities differ
| Vulnerability | Flaw and affected scope | Configuration or product detail | Exploitation evidence in the cited reporting |
|---|---|---|---|
| CVE-2026-85102 | Improper validation of certificate data during VPN negotiation; CERT-EU describes potential unauthenticated remote code execution on affected Security Gateway deployments. | Security Gateway/Spark deployments using Remote Access VPN or Site-to-Site VPN. Exact affected builds and hotfix thresholds are version-specific; consult the relevant Check Point advisory. | Check Point reported a wave of exploitation attempts against Spark customers beginning September 12, 2026. This is vendor-reported activity, not a count of exposed systems. |
| CVE-2026-85103 | Heap overflow in VPN certificate ASN.1 decoding; CERT-EU identifies Security Gateway and Security Management Server in the affected scope. | Exact affected builds and hotfix thresholds are version-specific; consult the relevant Check Point advisory. | The Check Point exploitation statement described in the cited reporting concerns CVE-2026-85102. It should not be treated as evidence that CVE-2026-85103 was exploited. |
CERT-EU reported a CVSS score of 9.8 for each CVE. NVD’s CVE-2026-85102 entry displayed the Check Point CNA’s 9.8 CVSS 3.1 score while marking NVD enrichment as pending; that page should not be presented as an independent NIST assessment of the score.
What is known about exploitation activity
According to Check Point, it released the CVE-2026-85102 fix on September 9, 2026, began observing a wave of exploitation attempts against Spark customers on September 12, and published an advisory about the activity on September 22. These dates describe the vendor’s disclosure, fix, and observation timeline; they do not quantify how many appliances were vulnerable, reached, or compromised.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Check Point named certificate subjects seen in its observations: CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global, and CN=vpnuser,OU=users,O=global. The vendor cautioned that the list is incomplete, so searches should not be limited to those exact strings.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteA Check Point CheckMates community post described suspicious certificate-based Remote Access VPN sessions followed by LDAP/LDAPS scanning in two customer environments before patching. That is anecdotal reporting, not a representative sample or vendor-confirmed case series; the post itself raised the possibility of another explanation. It cannot establish prevalence or be used to estimate internet exposure.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
How operators should check and respond
Verify whether the installation is in scope
- Identify the appliance role and product—such as Security Gateway, Spark, or Security Management Server—and record its release and Jumbo Hotfix take/build.
- Check the applicable Check Point security advisory for each CVE. Confirm the exact affected and fixed versions and any relevant VPN configuration conditions; do not infer status from a public-facing banner alone.
- Apply the version-specific vendor fix. CERT-EU recommends immediate hotfixing, prioritizing internet-facing perimeter appliances. Follow Check Point’s product-specific advisory for remediation, validation commands, mitigation alternatives, and upgrade guidance.
Review for suspicious activity
- Review logs for anomalous certificate-based Mobile Access logins, including certificates whose subjects do not match the three reported examples.
- For suspicious logged-in users, investigate subsequent activity, including internal port and service scanning.
- Treat these observations as hunting leads, not a complete indicator set or proof of compromise. Assess any findings against the organization’s broader incident-response process.
What a useful exposure report would need to publish
A credible scan-based count should make its scope and validation limits explicit. At minimum, readers need the observation date, scanner and identification method, coverage, deduplication approach, and a clear distinction between detected product fingerprints and systems confirmed to run an affected build with a vulnerable configuration. The public reporting described above does not provide those measurement details or a total.
Quick Recap
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

