<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Spark Firewall - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/spark-firewall/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 06:54:12 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/spark-firewall/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities in Check Point Security Appliances</title><link>https://feed.craftedsignal.io/briefs/2026-09-checkpoint-vulnerabilities/</link><pubDate>Thu, 10 Sep 2026 06:54:12 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-checkpoint-vulnerabilities/</guid><description>Check Point has disclosed critical vulnerabilities, including CVE-2026-85102 and CVE-2026-85103, affecting various Security Gateway, Management Server, and Spark Firewall deployments.</description><content:encoded><![CDATA[<p>On September 9, 2026, Check Point released security advisories identifying multiple critical vulnerabilities across its product line, specifically impacting Security Gateway, Security Management Server, and Spark Firewall appliances. The flaws include CVE-2026-85102, which allows for authentication bypass and remote code execution (RCE) via Site-to-Site or Remote Access VPN configurations, and CVE-2026-85103, a heap overflow vulnerability in ASN.1 decoding that also facilitates RCE. These vulnerabilities present significant risks to enterprise perimeter security, as successful exploitation could grant attackers unauthorized access to internal networks or complete control over the affected appliances. Defenders should prioritize patching and monitor for unusual traffic patterns associated with VPN termination points and ASN.1 processing services.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows unauthenticated attackers to achieve remote code execution on internet-facing Check Point infrastructure. This impact could lead to full system compromise, exfiltration of sensitive configuration data, lateral movement into protected internal network segments, and long-term persistence within the target organization's security boundary.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply vendor-supplied security patches or updates for Security Gateway, Security Management Server, and Spark Firewall as documented in the Check Point support articles linked below.</li>
<li>Monitor firewall and VPN logs for anomalous authentication attempts or unexpected process crashes that may indicate exploitation attempts (CVE-2026-85102, CVE-2026-85103).</li>
<li>Ensure management interfaces are isolated from the public internet and restricted to authorized management subnets.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>network-security</category><category>rce</category><category>high-confidence-source</category></item></channel></rss>