Our automated tracking framework flagged that CISA added CVE-2026-85102 (Check Point Multiple Products) to the Known Exploited Vulnerabilities (KEV) catalog on September 23, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.
What CISA Reported
CISA describes the flaw as follows: “Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.”
Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-85102 by September 25, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.
The Details
| CVE | CVE-2026-85102 |
| Vendor / product | Check Point Multiple Products |
| Vulnerability | Check Point Multiple Products Improper Certificate Validation Vulnerability |
| CVSS base score | 9.8 |
| Added to KEV | September 22, 2026 |
| Days public before listing (NVD → KEV lag) | 13 |
| Federal patch deadline | September 25, 2026 |
| Known ransomware use | No |
How This Compares to Check Point’s Track Record
This one was public for 13 days before CISA confirmed exploitation — longer than Check Point’s 0-day median, a vulnerability that sat exploitable in the open.
| Check Point in the CISA KEV catalog | Value |
|---|---|
| Tracked KEV entries | 5 |
| Median lag (public → KEV listing) | 0 days |
| 0-day rate (exploited at or before disclosure) | 60% |
| Entries tied to known ransomware campaigns | 2 |
For perspective, the median across all 1720 tracked KEV entries is 250 days — Check Point’s exploited vulnerabilities are flagged faster than the catalog average.
Other Recent Check Point KEV Additions
The most recent Check Point vulnerabilities CISA has confirmed as actively exploited, from our tracker:
| CVE | Product | Added to KEV | Lag (days) | Ransomware |
|---|---|---|---|---|
| CVE-2026-93616 | Multiple Products | September 22, 2026 | 0 | No |
| CVE-2026-16232 | SmartConsole | July 22, 2026 | 0 | No |
| CVE-2026-50751 | Security Gateway | June 8, 2026 | 0 | ⚠️ Yes |
| CVE-2024-24919 | Quantum Security Gateways | May 30, 2024 | 2 | ⚠️ Yes |
What This Means for Defenders
CISA has added CVE-2026-85102, an improper certificate validation vulnerability affecting Check Point Multiple Products, to its Known Exploited Vulnerabilities (KEV) catalog. With a CVSS base score of 9.8, it’s a critical concern for federal agencies, which must patch by September 25, 2026. This immediate KEV listing confirms active exploitation in the wild, making patching a top priority for all organizations using affected Check Point solutions.
CVE-2026-85102 was added to the KEV catalog just 13 days after public disclosure. This quick inclusion signals very early and aggressive exploitation. Organizations, especially those with internet-exposed Check Point deployments, are most vulnerable and should prioritize this patch. While there’s no known ransomware use for this CVE, its high severity and active exploitation demand extreme urgency.
Apply patches without delay. If immediate patching before the September 25 federal deadline isn’t feasible, restrict access to affected systems. Enhance network segmentation, strengthen monitoring for unusual activity originating from or targeting Check Point products, and ensure all network traffic is subject to strict validation rules to mitigate risks.
Related Coverage
- Critical Microsoft SharePoint Flaw CVE-2026-50522 (CVSS 9.8) Added to CISA KEV (July 2026)
- WordPress’s CVE-2026-63030 Was Exploited in 4 Days — Well Under Its 420-Day Median (July 2026)
How We Track This
This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.