CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

2026-012: Critical Vulnerabilities in Check Point Products

criticalCVE-2026-85102CVE-2026-85103
On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances. CERT-EU strongly recommends applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances.

Details

Source
CERT-EU Security Advisories (EU · eu · site)
Severity
critical
Published
2026-09-10
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cert.europa.eu/publications/security-advisories/2026-012/

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-85102coverage & exploitation statusNVD · CVE.org
CVE-2026-85103coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for 2026-012

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-EU Security Advisories