CTIPilot

Check Point Spark Firewall

product · product:check-point-spark-firewall

Coverage timeline
1
first 2026-09-10 → last 2026-09-10
Peak priority
high
1 high
Sources cited
3
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
4
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

Releases covered
Check Point Spark Firewall
ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-10/checkpoint-quantum-vpn-cert-preauth-rce-cvss98 · ATT&CK page ↗

Story timeline

  1. 2026-09-10Check Point Quantum Security Gateway / Management Server / Spark Firewall: two unauthenticated CVSS 9.8 pre-auth RCE flaws in VPN certificate processing (CVE-2026-85103 heap overflow, CVE-2026-85102 improper cert validation)
    trending-vulnerabilitiesTwo pre-auth code-execution flaws sit in the certificate-processing step every VPN negotiation runs before a user ever authenticates

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • support.checkpoint.com2 (67%)
  • forkast.news1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Check Point Spark Firewall (1)

2026-09-10 · view entry permalink →

Check Point Quantum Security Gateway / Management Server / Spark Firewall: two unauthenticated CVSS 9.8 pre-auth RCE flaws in VPN certificate processing (CVE-2026-85103 heap overflow, CVE-2026-85102 improper cert validation)

Check Point published two Critical-severity advisories (last modified 2026-09-09) for its VPN certificate-handling code, both triggered during certificate processing before authentication completes and both discovered internally with no external researcher credited (Check Point, advisory sk1000118, 2026-09-07; sk1000117, 2026-09-07). CVE-2026-85103 (CVSS 9.8) is "a heap overflow in the VPN certificate ASN.1 decoding flow" that "may allow a remote attacker to remotely execute arbitrary code on the management and Security Gateway" (Check Point, sk1000118). CVE-2026-85102 (CVSS 9.8, CWE-295 improper certificate validation) is an authentication-bypass-to-RCE in Remote Access and Site-to-Site VPN negotiation: "improper validation of certificate data during VPN negotiation may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway" (Check Point, sk1000117), reachable against the Security Gateway and Spark Firewall. Affected: R81.20, R82, R82.10, and the end-of-support R80/R80.10/R80.20/R80.30/R80.40/R81/R81.10 lines and their .x builds; R82.20 is confirmed not affected. "Both vulnerabilities were discovered internally by Check Point, and there are no reports of active exploitation as of September 9, 2026" (Forkast News, 2026-09-09); this is a distinct certificate-processing defect from the June 2026 IKEv1 key-exchange flaw (CVE-2026-50751) already on CISA KEV. Fix is delivered via Check Point LivePatch Take 24 (automatic if enabled) or Jumbo Hotfix Accumulator (R82.10 Take 44+, R82 Take 126+, R81.20 Take 166+), plus dedicated Spark Firewall builds (R82.00.10 Build 2325+, R81.10.17 Build 4968+). No workaround exists for the locally-managed Spark Firewall; for Site-to-Site VPN the only interim mitigation is disabling implied VPN rules and manually restricting UDP/500 and UDP/4500 to specific peer IPs, which does not apply to Remote Access VPN.

A heap overflow in the VPN certificate ASN.1 decoding flow may allow a remote attacker to remotely execute arbitrary code on the management and Security Gateway.

Check Point (vendor advisory sk1000118) 2026-09-07

Improper validation of certificate data during VPN negotiation may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway.

Check Point (vendor advisory sk1000117) 2026-09-07

Both vulnerabilities were discovered internally by Check Point, and there are no reports of active exploitation as of September 9, 2026.

Forkast News 2026-09-09
vulnerability10 Sep 04:45Zmulti-sourceOpen finding ↗