Check Point Patches Critical VPN Vulnerabilities Allowing Remote Code Execution
Check Point has addressed two critical vulnerabilities, **CVE-2026-85102** and **CVE-2026-85103**, affecting its firewall and management products. These flaws, both scoring 9.8 on the CVSS scale, could enable unauthenticated remote attackers to execute code under specific, undisclosed conditions. While **Check Point** states it found the flaws internally and has no indication of active exploitation, immediate patching is strongly recommended for affected **Security Gateways** and **Security Management Servers**.
Cybersecurity vendor **Check Point** has released patches for two critical vulnerabilities impacting its **Security Gateway** firewall appliances and **Security Management Server** consoles. These flaws, which stem from improper handling of VPN certificates, could allow unauthenticated remote code execution.
### Critical Vulnerabilities Identified
The first vulnerability, **CVE-2026-85102**, affects **Check Point Security Gateways** and involves a failure to properly validate certificate trust during VPN negotiation. The second, **CVE-2026-85103**, is a heap-based buffer overflow occurring during the decoding of ASN.1 structures within VPN certificates, impacting both **Quantum Security Management** and **Quantum Security Gateway** systems.
Both vulnerabilities have been assigned a CVSS score of 9.8, indicating their severe potential impact. **Check Point** disclosed these issues in a community notice on September 9 and began delivering fixes on the same day.
### Affected Products and Versions
**Check Point** has identified the following versions as affected:
* **R82.10** with Jumbo Hotfix Take 43 or below
* **R82** with Jumbo Hotfix Take 125 or below
* **R81.20** with Jumbo Hotfix Take 165 or below
An advisory from the **Canadian Centre for Cyber Security** also lists a broader set of products, including **Security Gateway**, **Security Management Server**, and **Spark Firewall** (Check Point's small-business line), without specific version details. Notably, the **Spark Firewall** is listed twice, with and without the condition of using Site-to-Site or Remote Access VPN.
Even systems with the VPN software blade turned off could be vulnerable to **CVE-2026-85103** if VPN certificates are present, as the issue lies in certificate processing.
### Remediation and Mitigation
Customers have two primary routes for applying the fixes:
1. **Check Point Live Patch**: Customers using this service should receive automatic protection as the rollout, which began on September 9, progresses. It is compatible with **R81.20**, **R82.00**, and **R82.10** Jumbo Hotfix levels.
2. **Jumbo Hotfix**: Customers are advised to install the latest Jumbo Hotfix for their deployed version once it becomes available.
Some customers running older versions, such as **R81.10**, have reported that neither Live Patch nor a specific Jumbo Hotfix is available, leaving them reliant on mitigation strategies. However, the provided mitigation advice, such as turning off implied rules for VPN, has been described as vague and lacking specific configuration guidance.
Concerns have also been raised regarding the automatic rollout's reach, with some gateways reportedly not receiving the latest updates, and issues with download links for the advisories.
### Historical Context and Lack of IoCs
These new vulnerabilities follow a series of critical flaws patched by **Check Point** in June and July, some of which were actively exploited in the wild. These included **CVE-2026-50751**, an authentication bypass in Remote Access VPN, and **CVE-2026-16232**, a **SmartConsole** authentication bypass, both added to **CISA's Known Exploited Vulnerabilities** catalog.
For the current flaws, **Check Point** has not published indicators of compromise (IoCs), stating that IoCs are typically provided for exploits that have been observed in the wild. The company maintains it has seen no evidence of external exploitation for **CVE-2026-85102** and **CVE-2026-85103**.
Further details, such as affected **Spark** or **Security Management** versions, specific build numbers containing the fix, and the precise conditions required for exploitation, remain undisclosed in the public advisories. There is also no explicit information on whether installing the fix addresses potential prior attacker access.