Check Point Gateway CVE-2026-85102: VPN Patch Checklist
September 23, 2026
CISA lists CVE-2026-85102 as a known exploited vulnerability, and Check Point says attacks against Spark Firewalls have been observed. The issue affects certain Security Gateway and Spark Firewall VPN configurations and can allow authentication bypass and remote code execution. Inventory the VPN gateways you operate, match each build to the current Check Point advisory, and apply the supported fix without waiting for a routine maintenance cycle.
Which gateways should be checked?
Check Point identifies Security Gateway and centrally or locally managed Spark Firewall systems using Site-to-Site or Remote Access VPN. Its affected-version list includes R81.20, R82, and R82.10, older end-of-support gateway releases, and Spark R81.10.x and R82.00.x. The vendor lists R82.20 as not affected. A release family alone is not a patch receipt: confirm the installed take or Spark build on every gateway and cluster member.
For Site-to-Site VPN, the vendor says certificate-based authentication must be in use or allowed for the issue to apply; a community that uses only pre-shared-key authentication is not vulnerable to this issue. Remote Access VPN and mixed deployments still need their own inventory. Do not infer that an entire estate is safe from one gateway’s configuration.
What fixed levels does Check Point list?
- Check Point LivePatch Take 26 for applicable R82.10, R82, and R81.20 gateway trains. Check Point notes a rare case where an earlier offline LivePatch package needs this enhanced take; verify the installed protection rather than assuming an earlier package is enough.
- Jumbo Hotfix Accumulator R82.10 Take 44 or later, R82 Take 126 or later, and R81.20 Take 166 or later. The advisory also lists R81.10 Take 190 or later; treat end-of-support trains as a migration priority and confirm vendor support before planning an update.
- For Spark Firewalls, R82.00.10 Build 2325 or later or R81.10.17 Build 4968 or later, as appropriate to the installed line. Check the live advisory before selecting a download or upgrade path.
Patch and verify without disrupting VPN users
- Record the gateway model, software train, exact take or build, VPN role, exposure, cluster membership, owner, and business-critical peer or remote-user dependencies. Prioritize internet-facing and Spark deployments.
- Use the Check Point-supported LivePatch, Jumbo Hotfix, or Spark build for that system. Plan a maintenance and recovery window, preserve the configuration needed for rollback, and account for cluster failover and remote-user communication.
- If an immediate update is impossible, review the vendor’s mitigation guidance with the network owner. Changes to VPN access rules can interrupt connectivity, and Check Point says its listed rule-based mitigations do not apply to locally managed Spark Firewall. Do not treat a CDN or web WAF as protection for gateway VPN traffic.
- After the change, verify the installed take or build on every gateway or cluster member, test authorized Site-to-Site and Remote Access VPN sessions, confirm expected failover and logging, and watch for unexpected configuration or authentication activity.
- If compromise is suspected, preserve relevant evidence and follow Check Point and CISA incident-triage guidance before cleanup. Do not share customer VPN details or raw logs publicly.
This is a gateway and VPN issue, distinct from CVE-2026-93616 in Check Point management and logging servers. For other confirmed priorities, see the Fix I.T. Phill security updates archive.
Sources: Check Point advisory sk1000117 (last modified September 23) and the CISA Known Exploited Vulnerabilities catalog (added September 22). This is defensive guidance based on those sources; Fix I.T. Phill has not independently confirmed exploitation in a customer environment.

