DEV Community

jeffrey
jeffrey

Posted on

Finding Affected Check Point VPN Deployments: Version Scope and ZoomEye Exposure for CVE-2026-85102

Finding Affected Check Point VPN Deployments: Version Scope and ZoomEye Exposure for CVE-2026-85102

Vulnerability overview

CERT-In Vulnerability Note CIVN-2026-0459, dated September 16, 2026, rates multiple Check Point VPN vulnerabilities as CRITICAL. The note names CVE-2026-85102 and CVE-2026-85103 and lists Security Gateway, Security Management Server, and Spark Firewall as affected products.
Before patching, most teams need to answer a prior question: which of our devices are actually in scope? This article works through the version boundaries and the exposure picture.

Mechanism and exploitation conditions

CERT-In attributes the flaws to improper certificate validation and a heap-based buffer overflow during VPN certificate processing. An unauthenticated remote attacker exploits them by supplying specially crafted certificate data during the VPN negotiation phase.
The negotiation phase runs before authentication, so reachability is the gating factor for an attacker rather than a credential. The disclosure does not publish a proof-of-concept, so exploitability in a given environment cannot be confirmed from the note alone.

Impact

CERT-In states that exploitation could allow arbitrary code execution, potentially resulting in complete compromise of the affected Security Gateway or Security Management Server, unauthorized access to sensitive information, and disruption of network operations.

Affected products and scope

Products: Security Gateway, Security Management Server, Spark Firewall.
Supported versions affected: R81.20, R82, R82.10, R81.10.x, R82.00.x.
End-of-support versions affected: R80 through R80.40, R81, R81.10.
Not affected: R82.20.
Two boundaries are worth stating plainly. R82.20 is out of scope, so a device on that release does not need this fix. Every other listed branch is in scope, including the end-of-support branches. The disclosure does not say whether both CVEs affect every product and version combination, so a device that matches any listed branch should be treated as affected until the vendor advisory says otherwise.

Exposure context

ZoomEye returns 1,852 instances for app="Check Point VPN". Read that number carefully. It counts assets that ZoomEye fingerprints as Check Point VPN. It does not tell you the version, the patch level, or whether the VPN negotiation service is exposed to an untrusted network. The population of genuinely vulnerable and reachable systems is a subset of that figure, and the disclosure does not quantify the subset.
A query for vul.cve="CVE-2026-85102" returned zero results. ZoomEye's CVE index and its product fingerprints are populated separately, so a zero CVE count alongside a large product count is not a contradiction.
For an internal inventory, the ZoomEye figure is useful as a scale reference for how widely the product is deployed, not as a list of affected hosts. The authoritative scope for a specific organization is its own asset inventory cross-referenced with the version list above.

Remediation and mitigations

Check Point published sk1000117 and sk1000118 with the fix guidance. Apply the update for each deployed product and version.
For devices on R80 through R80.40, R81, or R81.10, the fix path is an upgrade to a supported release, since those branches are out of support. Where the negotiation service cannot be restricted right away, limiting reachable peers to known addresses reduces the number of hosts that can deliver crafted certificate data. That is a scope reduction, not a repair.
After patching, verify the running build against the fixed version in the vendor advisory. Because the flaw triggers before authentication, authentication logs are unlikely to show a successful attempt.

References

Top comments (0)