Check Point Patches Critical 9.8-Rated VPN Certificate Flaws
Share
Check Point has released security updates to address two critical vulnerabilities in its firewall and management products. Both flaws, which carry a CVSS score of 9.8, could allow an unauthenticated remote attacker to perform remote code execution (RCE) on affected systems.
The vulnerabilities involve the way the company’s products handle VPN certificates. While Check Point stated that the flaws could only be exploited under “specific conditions” that have not been fully detailed, the high severity rating reflects the potential for unauthorised attackers to gain control over security infrastructure.
Technical details of the vulnerabilities
The first vulnerability, CVE-2026-85102, relates to a failure to properly validate certificate trust during VPN negotiation. This flaw specifically affects Check Point Security Gateways, which serve as firewall appliances.
The second flaw, CVE-2026-85103, is a heap-based buffer overflow that occurs while the product decodes the Abstract Syntax Notation One (ASN.1) structure of a VPN certificate. This vulnerability affects both the Security Gateways and the Security Management Server, the console used for device configuration.
Notably, Check Point staff indicated that because the issue involves certificate processing, it could theoretically be triggered in environments where the VPN software blade is disabled, provided that VPN certificates are still present on the system.
Affected products and patching
The vulnerabilities impact several Quantum software branches. Based on current technical records, the affected versions include:
- R82.10 with Jumbo Hotfix Take 43 or below
- R82 with Jumbo Hotfix Take 125 or below
- R81.20 with Jumbo Hotfix Take 165 or below
The Canadian Centre for Cyber Security has also issued an advisory noting that Check Point’s Spark Firewall line, which is designed for small businesses, is also affected. This includes deployments using Site-to-Site or Remote Access VPN.
Check Point has provided two primary methods for remediation. Customers can use Check Point Live Patch for automatic protection or install the latest available Jumbo Hotfix for their specific version. Some users have reported difficulties with the automatic rollout and have noted that provided mitigation guidance for certain versions has been difficult to implement without disrupting remote access.
Context of recent security disclosures
This disclosure follows a series of critical security patches issued by Check Point earlier this year. In June and July 2026, the company addressed vulnerabilities (CVE-2026-50751 and CVE-2026-16232) that were confirmed to be exploited in the wild.
Those previous flaws involved authentication bypasses in Remote Access VPN and SmartConsole. Both were subsequently added to the CISA Known Exploited Vulnerabilities catalogue. For the current vulnerabilities, Check Point has stated it has found no evidence of active exploitation to date.




Leave a Reply