<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Possible CVE-2026-85102 exploitation – unauthorized VPN sessions and LDAP/LDAPS scanning in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Possible-CVE-2026-85102-exploitation-unauthorized-VPN-sessions/m-p/282335#M14143</link>
    <description>&lt;P class=""&gt;Hi CheckMates,&lt;/P&gt;&lt;P&gt;I would like to compare notes with the community regarding the recently disclosed VPN vulnerabilities, specifically CVE-2026-85102 / sk1000117.&lt;/P&gt;&lt;P&gt;On September 14 we observed very similar suspicious activity on &lt;STRONG&gt;two separate Check Point gateways in two completely independent customer environments&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Before the gateways were updated, the logs show:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Successful Remote Access VPN login events&lt;/LI&gt;&lt;LI&gt;Authentication method shown as &lt;STRONG&gt;Certificate&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Certificate CNs such as vpnuser / vpn-user&lt;/LI&gt;&lt;LI&gt;A 172.16.10.x Remote Access VPN IP being assigned&lt;/LI&gt;&lt;LI&gt;Immediately afterwards, large numbers of VPN Decrypt connections towards internal networks&lt;/LI&gt;&lt;LI&gt;Systematic scanning of internal IP ranges, mainly on &lt;STRONG&gt;TCP/389 (LDAP)&lt;/STRONG&gt; and &lt;STRONG&gt;TCP/636 (LDAPS)&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;In both environments the scanning pattern was highly automated&lt;/LI&gt;&lt;LI&gt;At one point, very similar scanning activity occurred on both unrelated gateways almost simultaneously&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;We do not recognize these VPN sessions or certificates as legitimate user activity.&lt;/P&gt;&lt;P&gt;After installing the fix referenced in sk1000117, we have &lt;STRONG&gt;not observed any further successful sessions of this type&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;We opened a TAC case and had a remote session with Check Point Support. TAC confirmed that the gateway is protected once the fix is installed. However, my concern is specifically about &lt;STRONG&gt;post-compromise remediation for activity that occurred before the fix was installed&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;I therefore have a few questions for the community and, if possible, Check Point:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Has anyone else seen successful certificate-based Remote Access VPN sessions followed by LDAP/LDAPS scanning in relation to these vulnerabilities?&lt;/LI&gt;&lt;LI&gt;Is this logging pattern consistent with exploitation of CVE-2026-85102, or could there be another explanation?&lt;/LI&gt;&lt;LI&gt;If unauthorized VPN access occurred before patching, is installing the fix considered sufficient remediation, or should the gateway be rebuilt/re-imaged?&lt;/LI&gt;&lt;LI&gt;Are there specific Gaia / VPN / system logs or IOCs that should be checked to determine whether code execution or persistence occurred on the gateway itself?&lt;/LI&gt;&lt;LI&gt;Should local gateway credentials, certificates or other secrets be rotated in this scenario?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I have preserved the gateway logs and can provide &lt;STRONG&gt;sanitized/anonymized log samples and timestamps&lt;/STRONG&gt; if useful.&lt;/P&gt;&lt;P&gt;I am deliberately not posting customer names, public IP addresses or internal addressing at this stage.&lt;/P&gt;&lt;P&gt;Thanks in advance for any insight.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Sep 2026 04:48:07 GMT</pubDate>
    <dc:creator>sander143188</dc:creator>
    <dc:date>2026-09-15T04:48:07Z</dc:date>
    <item>
      <title>Possible CVE-2026-85102 exploitation – unauthorized VPN sessions and LDAP/LDAPS scanning</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Possible-CVE-2026-85102-exploitation-unauthorized-VPN-sessions/m-p/282335#M14143</link>
      <description>&lt;P class=""&gt;Hi CheckMates,&lt;/P&gt;&lt;P&gt;I would like to compare notes with the community regarding the recently disclosed VPN vulnerabilities, specifically CVE-2026-85102 / sk1000117.&lt;/P&gt;&lt;P&gt;On September 14 we observed very similar suspicious activity on &lt;STRONG&gt;two separate Check Point gateways in two completely independent customer environments&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Before the gateways were updated, the logs show:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Successful Remote Access VPN login events&lt;/LI&gt;&lt;LI&gt;Authentication method shown as &lt;STRONG&gt;Certificate&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Certificate CNs such as vpnuser / vpn-user&lt;/LI&gt;&lt;LI&gt;A 172.16.10.x Remote Access VPN IP being assigned&lt;/LI&gt;&lt;LI&gt;Immediately afterwards, large numbers of VPN Decrypt connections towards internal networks&lt;/LI&gt;&lt;LI&gt;Systematic scanning of internal IP ranges, mainly on &lt;STRONG&gt;TCP/389 (LDAP)&lt;/STRONG&gt; and &lt;STRONG&gt;TCP/636 (LDAPS)&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;In both environments the scanning pattern was highly automated&lt;/LI&gt;&lt;LI&gt;At one point, very similar scanning activity occurred on both unrelated gateways almost simultaneously&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;We do not recognize these VPN sessions or certificates as legitimate user activity.&lt;/P&gt;&lt;P&gt;After installing the fix referenced in sk1000117, we have &lt;STRONG&gt;not observed any further successful sessions of this type&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;We opened a TAC case and had a remote session with Check Point Support. TAC confirmed that the gateway is protected once the fix is installed. However, my concern is specifically about &lt;STRONG&gt;post-compromise remediation for activity that occurred before the fix was installed&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;I therefore have a few questions for the community and, if possible, Check Point:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Has anyone else seen successful certificate-based Remote Access VPN sessions followed by LDAP/LDAPS scanning in relation to these vulnerabilities?&lt;/LI&gt;&lt;LI&gt;Is this logging pattern consistent with exploitation of CVE-2026-85102, or could there be another explanation?&lt;/LI&gt;&lt;LI&gt;If unauthorized VPN access occurred before patching, is installing the fix considered sufficient remediation, or should the gateway be rebuilt/re-imaged?&lt;/LI&gt;&lt;LI&gt;Are there specific Gaia / VPN / system logs or IOCs that should be checked to determine whether code execution or persistence occurred on the gateway itself?&lt;/LI&gt;&lt;LI&gt;Should local gateway credentials, certificates or other secrets be rotated in this scenario?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I have preserved the gateway logs and can provide &lt;STRONG&gt;sanitized/anonymized log samples and timestamps&lt;/STRONG&gt; if useful.&lt;/P&gt;&lt;P&gt;I am deliberately not posting customer names, public IP addresses or internal addressing at this stage.&lt;/P&gt;&lt;P&gt;Thanks in advance for any insight.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 04:48:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Possible-CVE-2026-85102-exploitation-unauthorized-VPN-sessions/m-p/282335#M14143</guid>
      <dc:creator>sander143188</dc:creator>
      <dc:date>2026-09-15T04:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Possible CVE-2026-85102 exploitation – unauthorized VPN sessions and LDAP/LDAPS scanning</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Possible-CVE-2026-85102-exploitation-unauthorized-VPN-sessions/m-p/282420#M14148</link>
      <description>&lt;P&gt;My personal take is that the observed logs seem consistent with someone exploiting&amp;nbsp;&lt;SPAN&gt;CVE-2026-85102 and then attempting to pivot further into the environment.&lt;BR /&gt;As this vulnerability was discovered internally, we don't have IoCs to share.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2026 15:03:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Possible-CVE-2026-85102-exploitation-unauthorized-VPN-sessions/m-p/282420#M14148</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-09-16T15:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: Possible CVE-2026-85102 exploitation – unauthorized VPN sessions and LDAP/LDAPS scanning</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Possible-CVE-2026-85102-exploitation-unauthorized-VPN-sessions/m-p/282440#M14150</link>
      <description>&lt;P&gt;3. and 5. -&amp;gt;&amp;nbsp;&lt;SPAN&gt;may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;So if you want to be sure, yes reinstall. I think you cannot be 100% sure if they run a code yes or no.&lt;/P&gt;
&lt;P&gt;But in the end, recently there are many CVE's for a lot of vendors, it is not manageable to every time clean install the system and change all the passwords, certificates etc. Of course if the CVE states access was possible to the exposed system&lt;/P&gt;
&lt;P&gt;I would ask TAC to advise what to do if they indeed abused this CVE. Just assume they have been able to run all the code they wanted, what would TAC advise be?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to make sure the changes are quite a lot think like:&lt;/P&gt;
&lt;P&gt;Change all PSK for all tunnels.&lt;/P&gt;
&lt;P&gt;Renew all certificates&lt;/P&gt;
&lt;P&gt;Change passwords, SNMP ssh access , GRUB, expert etc.&lt;/P&gt;
&lt;P&gt;Rotate ICA, renew VPN cert, platform portal,SSL decryp cert etc.&lt;/P&gt;
&lt;P&gt;Check out AD servers, the logs, reset service accounts. Maybe check out the service accounts that the check point uses&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2026 18:57:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Possible-CVE-2026-85102-exploitation-unauthorized-VPN-sessions/m-p/282440#M14150</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-09-16T18:57:13Z</dc:date>
    </item>
  </channel>
</rss>

