{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/security-management-server/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85102"},{"cvss":9.8,"id":"CVE-2026-85103"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Security Gateway","Spark Firewall","Security Management Server"],"_cs_severities":["high"],"_cs_tags":["vulnerability","network-security","rce","high-confidence-source"],"_cs_type":"advisory","_cs_vendors":["Check Point"],"content_html":"\u003cp\u003eOn September 9, 2026, Check Point released security advisories identifying multiple critical vulnerabilities across its product line, specifically impacting Security Gateway, Security Management Server, and Spark Firewall appliances. The flaws include CVE-2026-85102, which allows for authentication bypass and remote code execution (RCE) via Site-to-Site or Remote Access VPN configurations, and CVE-2026-85103, a heap overflow vulnerability in ASN.1 decoding that also facilitates RCE. These vulnerabilities present significant risks to enterprise perimeter security, as successful exploitation could grant attackers unauthorized access to internal networks or complete control over the affected appliances. Defenders should prioritize patching and monitor for unusual traffic patterns associated with VPN termination points and ASN.1 processing services.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows unauthenticated attackers to achieve remote code execution on internet-facing Check Point infrastructure. This impact could lead to full system compromise, exfiltration of sensitive configuration data, lateral movement into protected internal network segments, and long-term persistence within the target organization's security boundary.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply vendor-supplied security patches or updates for Security Gateway, Security Management Server, and Spark Firewall as documented in the Check Point support articles linked below.\u003c/li\u003e\n\u003cli\u003eMonitor firewall and VPN logs for anomalous authentication attempts or unexpected process crashes that may indicate exploitation attempts (CVE-2026-85102, CVE-2026-85103).\u003c/li\u003e\n\u003cli\u003eEnsure management interfaces are isolated from the public internet and restricted to authorized management subnets.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T06:54:12Z","date_published":"2026-09-10T06:54:12Z","id":"https://feed.craftedsignal.io/briefs/2026-09-checkpoint-vulnerabilities/","summary":"Check Point has disclosed critical vulnerabilities, including CVE-2026-85102 and CVE-2026-85103, affecting various Security Gateway, Management Server, and Spark Firewall deployments.","title":"Critical Vulnerabilities in Check Point Security Appliances","url":"https://feed.craftedsignal.io/briefs/2026-09-checkpoint-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Security Management Server","version":"https://jsonfeed.org/version/1.1"}