HackMyIP
← Back to News
2026-09-10 The Hacker News

Check Point Patches Two Critical 9.8-Rated VPN Certificate Flaws

VulnerabilityAuthentication

Check Point has disclosed and patched two critical vulnerabilities affecting how its firewall and management products handle VPN certificates, both carrying a maximum CVSS score of 9.8. The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, could allow an unauthenticated remote attacker to execute arbitrary code on affected appliances, though Check Point says exploitation requires "specific conditions" that it has declined to detail publicly. The company disclosed both issues on September 9 in a customer advisory and began delivering fixes the same day, and has stated there is no evidence either vulnerability has been exploited in the wild.

The first flaw, CVE-2026-85102, stems from a failure to properly validate certificate trust during VPN negotiation and enables unauthenticated remote code execution on Security Gateway appliances. The second, CVE-2026-85103, is a heap-based buffer overflow triggered while the product decodes the ASN.1 structure of an incoming VPN certificate, and affects both Quantum Security Gateway and Quantum Security Management systems. Both records were self-assigned and self-scored by Check Point, and list the same affected versions: R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, and R81.20 with Jumbo Hotfix Take 165 or below. A separate advisory from the Canadian Centre for Cyber Security broadens the affected product list to include the Spark Firewall small-business line, noting separate conditions for deployments using Site-to-Site or Remote Access VPN versus those without.

In a community thread, a Check Point staffer clarified that CVE-2026-85103 could theoretically be triggered even on gateways with the VPN blade disabled, because the underlying issue lives in certificate processing rather than the VPN tunnel itself. Administrators running unpatched R81.10 deployments should note that Check Point's Live Patch and Jumbo Hotfix remediation paths explicitly cover only R81.20, R82.00, and R82.10, leaving R81.10 effectively out of supported repair routes. Network defenders should also verify exposure across internet-facing gateways using a port scanner to confirm whether management and VPN services are reachable, and review certificate-handling configurations carefully given the trust-validation failure at the core of CVE-2026-85102.

Check Point offers two patching routes. Check Point Live Patch delivers protection automatically starting September 9 and can be layered on top of any Jumbo Hotfix level in R81.20, R82.00, and R82.10. Customers preferring a permanent fix are directed to install the latest Jumbo Hotfix for their deployed version. Given the certificate-handling roots of both flaws, security teams should also validate the integrity of their broader TLS and VPN trust chains using a SSL/TLS checker, and verify that no unauthorized VPN or proxy tunnels are bypassing perimeter controls with a VPN/proxy detector. Organizations unable to patch immediately should consider disabling VPN certificate parsing where operationally feasible and tightening network access control lists around management interfaces.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

SSL/TLS Checker →Security Headers Check →VPN & Proxy Detector →

Related Guides

Learn the background behind this story:

What is SSL/TLS? →HTTPS explained →HTTP security headers explained →