VYPR
patchPublished Sep 10, 2026· 2 sources

Check Point Patches Two Critical VPN Vulnerabilities Enabling Remote Code Execution

Check Point has released patches for two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both rated CVSS 9.8 and capable of unauthenticated remote code execution.

Check Point Software has announced the patching of two critical vulnerabilities affecting its VPN products, identified as CVE-2026-85102 and CVE-2026-85103. Both flaws carry a maximum CVSS score of 9.8 and can lead to unauthenticated remote code execution under specific circumstances. The company's internal research team discovered these vulnerabilities, and as of the disclosure, Check Point has reported no evidence of active exploitation in the wild or the availability of public proof-of-concept code.

CVE-2026-85102 is a vulnerability rooted in improper certificate trust validation during the VPN negotiation process, categorized under CWE-295. According to Check Point's advisory sk1000117, the flaw fails to adequately validate the trust of a presented certificate. This allows an unauthenticated attacker to manipulate the VPN negotiation to the extent that they can execute arbitrary code on the affected Security Gateway. This vulnerability impacts both Remote Access VPN and Site-to-Site VPN configurations.

In contrast, CVE-2026-85103 is a heap-based buffer overflow vulnerability (CWE-122) that is triggered during the parsing of a VPN certificate's ASN.1 structure. Detailed in advisory sk1000118, this bug enables a remote attacker to initiate the overflow by simply sending a malicious certificate. Successful exploitation could lead to code execution on both Quantum Security Gateway and Quantum Security Management systems.

The vulnerabilities affect a range of Check Point products, including Security Gateway, Security Management Server, and Spark Firewall deployments across multiple release branches. Specifically, versions R81.20, R82, and R82.10 with Jumbo Hotfix Takes below the newly patched builds are impacted, as are several end-of-support versions such as R80.40 and R81. Check Point has confirmed that R82.20 is not affected by these particular issues.

While CVE-2026-85102 primarily targets Security Gateways involved in VPN connections, CVE-2026-85103 has a broader impact, affecting both gateway and management infrastructure. Organizations utilizing Check Point's Live Patch service will receive automatic protection, as the rollout of the fix began on September 9, 2026. For administrators who do not have Live Patch enabled, manual installation of the latest Jumbo Hotfix Accumulator is required. This includes R82.10 Take 44 or higher, R82 Take 126 or higher, or R81.20 Take 166 or higher, along with specific builds for Spark Firewall.

For Site-to-Site VPN deployments that cannot be patched immediately, Check Point recommends a workaround involving the restriction of UDP ports 500 and 4500 to known peer IP addresses and disabling implied VPN rules. However, this mitigation is not applicable to Remote Access VPN scenarios, and no interim solution is available for locally managed Spark Firewalls.

It is important to note that these newly patched vulnerabilities are distinct from CVE-2026-50751, an earlier disclosed IKEv1 authentication bypass vulnerability that has been linked to Qilin ransomware activity. Given the critical severity and network-exploitable nature of CVE-2026-85102 and CVE-2026-85103, security teams operating Check Point infrastructure are strongly advised to prioritize immediate patching to mitigate potential risks.

The new article provides further details on the affected versions, specifying R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, and R81.20 with Jumbo Hotfix Take 165 or below. It also highlights that the Canadian Center for Cyber Security advisory lists a broader set of products including Spark Firewall, and notes that the vulnerabilities could theoretically be triggered even without an active VPN if VPN certificates are present. The article also details customer issues with automatic patch rollouts and broken download links for advisories.

Synthesized by Vypr AI