Check Point released emergency security updates on September 9, 2026, to address two critical-severity flaws. These critical Check Point VPN vulnerabilities allow unauthenticated attackers to achieve remote code execution. Security teams discovered the issues internally, and no active in-the-wild exploitation currently exists.
- Product: checkpoint Quantum Security Gateway
- Vulnerabilities: 2 flaws (CVE-2026-85102, CVE-2026-85103)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: Improper Certificate Validation in
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-85102 | 9.8 | CWE-295 | Not exploited |
| CVE-2026-85103 | 9.8 | CWE-122 | Not exploited |
Why This Threat Matters
Industry estimates show Check Point secures more than 100,000 organizations worldwide. Network security appliances serve as the primary defensive barrier against perimeter incursions. Therefore, flaws in perimeter defense hardware present severe risks to enterprise operations. If an attacker exploits these Check Point VPN vulnerabilities, they can seize complete administrative control over gateways. Consequently, unauthorized actors could penetrate internal network zones and access confidential corporate data.
How the Attack Works
The first flaw, CVE-2026-85102, involves improper certificate validation during session establishment. According to the sk1000117 security advisory, “Improper validation of certificate data during VPN negotiation may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway.”
Meanwhile, the second vulnerability, CVE-2026-85103, stems from a memory corruption bug. The vendor confirmed in the sk1000118 security advisory that “A heap overflow in the VPN certificate ASN.1 decoding flow may allow a remote attacker to remotely execute arbitrary code on the management and Security Gateway.” Both flaws trigger over standard network channels without prior authentication.
Affected Versions
These Check Point VPN vulnerabilities affect Security Gateway, Security Management Server, and Spark Firewall models. Impacted releases include versions R81.20, R82, and R82.10. Older end-of-support versions from R80 through R81.10 also contain the vulnerable code. Conversely, release R82.20 remains unaffected. Researchers have confirmed no public proof-of-concept exploits for either issue.
Patch and Mitigation Steps
Check Point resolved both flaws through its automated LivePatch service. Systems with LivePatch enabled will receive protection automatically. Alternatively, administrators can install the designated Jumbo Hotfix Accumulator packages for their release branches. For manual mitigation on Site-to-Site VPNs, administrators should disable implied VPN rules. Then, restrict UDP ports 500 and 4500 to specific peer IP addresses. Administrators should apply these updates immediately to secure their network perimeters.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!