CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Check Point security advisory (AV26-902)

unknownCVE-2026-85102CVE-2026-85103
Serial Number: AV26-902 Date: September 9, 2026 As of September 9, 2026, Check Point is affected by vulnerabilities in the following products: Security Gateway Multiple versions Check Point Spark Firewall using Site to Site VPN or Remote Access VPN Multiple versions Security Management Server Multiple versions Check Point Spark Firewall Multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-85102 - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN CVE-2026-85103 - ASN.1 decoding heap overflow leading to a remote code execution Check Point Security

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-09-09
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-902

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-85102coverage & exploitation statusNVD · CVE.org
CVE-2026-85103coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security