Download Privacy Needle App

Type to search

Cybersecurity

Check Point Patches Critical 9.8-Rated VPN Certificate Flaws

Share

Check Point has released security updates to address two critical vulnerabilities in its firewall and management products. Both flaws, which carry a CVSS score of 9.8, could allow an unauthenticated remote attacker to perform remote code execution (RCE) on affected systems.

The vulnerabilities involve the way the company’s products handle VPN certificates. While Check Point stated that the flaws could only be exploited under “specific conditions” that have not been fully detailed, the high severity rating reflects the potential for unauthorised attackers to gain control over security infrastructure.

Technical details of the vulnerabilities

The first vulnerability, CVE-2026-85102, relates to a failure to properly validate certificate trust during VPN negotiation. This flaw specifically affects Check Point Security Gateways, which serve as firewall appliances.

The second flaw, CVE-2026-85103, is a heap-based buffer overflow that occurs while the product decodes the Abstract Syntax Notation One (ASN.1) structure of a VPN certificate. This vulnerability affects both the Security Gateways and the Security Management Server, the console used for device configuration.

Notably, Check Point staff indicated that because the issue involves certificate processing, it could theoretically be triggered in environments where the VPN software blade is disabled, provided that VPN certificates are still present on the system.

Affected products and patching

The vulnerabilities impact several Quantum software branches. Based on current technical records, the affected versions include:

  • R82.10 with Jumbo Hotfix Take 43 or below
  • R82 with Jumbo Hotfix Take 125 or below
  • R81.20 with Jumbo Hotfix Take 165 or below

The Canadian Centre for Cyber Security has also issued an advisory noting that Check Point’s Spark Firewall line, which is designed for small businesses, is also affected. This includes deployments using Site-to-Site or Remote Access VPN.

Check Point has provided two primary methods for remediation. Customers can use Check Point Live Patch for automatic protection or install the latest available Jumbo Hotfix for their specific version. Some users have reported difficulties with the automatic rollout and have noted that provided mitigation guidance for certain versions has been difficult to implement without disrupting remote access.

Context of recent security disclosures

This disclosure follows a series of critical security patches issued by Check Point earlier this year. In June and July 2026, the company addressed vulnerabilities (CVE-2026-50751 and CVE-2026-16232) that were confirmed to be exploited in the wild.

Those previous flaws involved authentication bypasses in Remote Access VPN and SmartConsole. Both were subsequently added to the CISA Known Exploited Vulnerabilities catalogue. For the current vulnerabilities, Check Point has stated it has found no evidence of active exploitation to date.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.