Our automated tracking framework flagged that CISA added CVE-2026-85102 (Check Point Multiple Products) to the Known Exploited Vulnerabilities (KEV) catalog on September 23, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.

What CISA Reported

CISA describes the flaw as follows: “Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.”

Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-85102 by September 25, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.

The Details

CVE CVE-2026-85102
Vendor / product Check Point Multiple Products
Vulnerability Check Point Multiple Products Improper Certificate Validation Vulnerability
CVSS base score 9.8
Added to KEV September 22, 2026
Days public before listing (NVD → KEV lag) 13
Federal patch deadline September 25, 2026
Known ransomware use No

How This Compares to Check Point’s Track Record

This one was public for 13 days before CISA confirmed exploitation — longer than Check Point’s 0-day median, a vulnerability that sat exploitable in the open.

Check Point in the CISA KEV catalog Value
Tracked KEV entries 5
Median lag (public → KEV listing) 0 days
0-day rate (exploited at or before disclosure) 60%
Entries tied to known ransomware campaigns 2

For perspective, the median across all 1720 tracked KEV entries is 250 days — Check Point’s exploited vulnerabilities are flagged faster than the catalog average.

Other Recent Check Point KEV Additions

The most recent Check Point vulnerabilities CISA has confirmed as actively exploited, from our tracker:

CVE Product Added to KEV Lag (days) Ransomware
CVE-2026-93616 Multiple Products September 22, 2026 0 No
CVE-2026-16232 SmartConsole July 22, 2026 0 No
CVE-2026-50751 Security Gateway June 8, 2026 0 ⚠️ Yes
CVE-2024-24919 Quantum Security Gateways May 30, 2024 2 ⚠️ Yes

What This Means for Defenders

CISA has added CVE-2026-85102, an improper certificate validation vulnerability affecting Check Point Multiple Products, to its Known Exploited Vulnerabilities (KEV) catalog. With a CVSS base score of 9.8, it’s a critical concern for federal agencies, which must patch by September 25, 2026. This immediate KEV listing confirms active exploitation in the wild, making patching a top priority for all organizations using affected Check Point solutions.

CVE-2026-85102 was added to the KEV catalog just 13 days after public disclosure. This quick inclusion signals very early and aggressive exploitation. Organizations, especially those with internet-exposed Check Point deployments, are most vulnerable and should prioritize this patch. While there’s no known ransomware use for this CVE, its high severity and active exploitation demand extreme urgency.

Apply patches without delay. If immediate patching before the September 25 federal deadline isn’t feasible, restrict access to affected systems. Enhance network segmentation, strengthen monitoring for unusual activity originating from or targeting Check Point products, and ensure all network traffic is subject to strict validation rules to mitigate risks.

Related Coverage

How We Track This

This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.