Check Point patches RCE and policy bypass flaws
CERT-FR advisory details Check Point Security Gateway/Management/Spark vulnerabilities enabling remote code execution and security policy bypass; patches available.
CERT-FR issued an advisory covering multiple vulnerabilities in Check Point Security Gateway, Security Management Server, and Spark Firewall products. The flaws allow an attacker to achieve remote arbitrary code execution and bypass configured security policies, tracked as CVE-2026-85102 and CVE-2026-85103. Affected versions include R81.20, R82, and R82.10 prior to their respective 'take 24' builds.
Check Point notes that older versions (R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10) are end-of-service and will not receive patches, meaning organizations still running these releases have no vendor remediation path and should prioritize migration to a supported, patched version. No in-the-wild exploitation is mentioned in the advisory. Defenders operating Check Point Security Gateway, Security Management, or Spark Firewalls should apply the take 24 updates for their respective R81.20/R82/R82.10 branches per Check Point's sk1000117 and sk1000118 bulletins, and treat unsupported legacy versions as a priority upgrade risk.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1152
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free