VMTech
Discuss a project

Check Point fixes two critical VPN certificate RCE vulnerabilities

Check Point fixes two critical VPN certificate RCE vulnerabilities

Check Point has released fixes for two critical VPN certificate vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in its firewall and management products. Both bugs carry a CVSS score of 9.8 and could allow an unauthenticated remote attacker to execute code under specific conditions that the company has not detailed.

The company disclosed the issues to its customer community on September 9 and began delivering fixes that day. Check Point said it discovered both vulnerabilities internally and had no indication that either had been exploited.

Two certificate-processing paths

CVE-2026-85102 is a certificate-trust validation flaw during VPN negotiation. Its CVE record states that an unauthenticated remote attacker may be able to execute code on a Check Point Security Gateway.

CVE-2026-85103 is a heap-based buffer overflow during decoding of an ASN.1 structure in a VPN certificate. The vulnerability may permit unauthenticated remote code execution on Quantum Security Management and Quantum Security Gateway systems.

Check Point assigned the CVE identifiers and severity scores. The affected-version lists in both records identify R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, and R81.20 with Jumbo Hotfix Take 165 or below. Those lists describe affected builds, rather than the builds containing fixes.

Patch availability and scope questions

Check Point offers remediation through Live Patch or the latest Jumbo Hotfix for the deployed version. The company said Live Patch protection began rolling out on September 9. In a customer discussion, a Check Point employee said Live Patch could be installed over any Jumbo Hotfix level in R81.20, R82.00, and R82.10.

The public material leaves several operational details unresolved. Check Point's notices do not specify affected Security Management or Spark Firewall versions, identify the fixed builds, or explain the conditions required for exploitation. A Canadian Center for Cyber Security advisory listed Security Gateway, Security Management Server, and Spark Firewall, including Spark deployments with and without Site-to-Site or Remote Access VPN, but did not list versions.

One Check Point staff response also noted that CVE-2026-85103 concerns certificate processing and could theoretically be triggered where VPN certificates are present even if the VPN software blade is disabled. Customers running R81.10 reported that neither a Jumbo Hotfix nor Live Patch was available for that branch, and questions about mitigation steps and effects on remote users were unanswered in the discussion.

What teams should verify

Several customers also reported delayed Live Patch delivery or unavailable advisory download links. Check Point directs customers to advisories sk1000117 and sk1000118 for affected-product, mitigation, and remediation guidance. It has not released indicators of compromise, and its notices do not address whether applying a fix would remove access already obtained by an attacker.

For businesses operating Check Point infrastructure, the practical next step is to inventory deployed Quantum and Spark products, verify the installed Jumbo Hotfix and Live Patch status, and confirm a supported remediation path for every branch before relying on mitigation alone.

#cybersecurity#vulnerability#networksecurity#checkpoin
Open analytics
On the site 0 views
min read 4 10.09.2026
Instagram

Check Point fixes two critical VPN certificate RCE vulnerabilities

Open the post on Instagram ↗