Illustrative image generated with AI
Check Point Patches Two Critical VPN Certificate Flaws Allowing Unauthenticated RCE
Check Point fixes two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, with CVSS 9.8, enabling unauthenticated RCE on Security Gateways and Management.
Text generated by artificial intelligence, published without human review. AI transparency
Check Point disclosed two critical certificate-processing vulnerabilities on September 9, 2026, and began distributing protections that day. Both flaws carry a CVSS score of 9.8 and may allow unauthenticated attackers to execute code remotely on affected security systems.
The company says exploitation requires “specific conditions,” but it has not explained what those conditions are. Check Point discovered both vulnerabilities internally and has found no evidence of attacks exploiting them.
No indicators of compromise have been released.
Two certificate flaws expose gateways and management systems
The first vulnerability, CVE-2026-85102, involves inadequate validation of certificate trust during VPN negotiation. Successful exploitation can result in unauthenticated remote code execution on a Check Point Security Gateway.
The second, CVE-2026-85103, is a heap-based buffer overflow in the code that decodes the ASN.1 structure of a VPN certificate. It affects Quantum Security Management and Quantum Security Gateway systems and can also lead to unauthenticated remote code execution.
Both vulnerabilities have the following severity data:
- CVSS score: 9.8
- CVSS vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
That vector describes a network-reachable attack requiring no privileges or user interaction, with potentially complete effects on confidentiality, integrity, and availability. Check Point assigned the identifiers and scores. CWE classifications have not been published for either vulnerability.
The technical paths differ. CVE-2026-85102 concerns whether the gateway correctly establishes trust in a certificate presented during VPN negotiation. CVE-2026-85103 instead targets memory handling while the system parses certificate data encoded using ASN.1.
The latter may not be limited to systems with the VPN software blade enabled. A Check Point employee told customers that certificate processing could theoretically expose an environment where VPN certificates are present, even if the blade itself is disabled.
Check Point has not disclosed whether an attacker needs a reachable VPN interface, a specially configured certificate chain, or another deployment-specific prerequisite. It has also not published proof-of-concept code or packet-level details.
R81.20, R82, and R82.10 builds are affected
Check Point’s records give the same affected-version list for both vulnerabilities:
| Product branch | Affected Jumbo Hotfix level |
|---|---|
| R82.10 | Take 43 or below |
| R82 | Take 125 or below |
| R81.20 | Take 165 or below |
These numbers identify affected releases, not the first fixed Jumbo Hotfix builds. Check Point has not specified which Jumbo Hotfix Takes contain the permanent corrections.
The records cover only those three Quantum branches. They do not provide version information for older releases or other product families.
A Canadian Center for Cyber Security advisory named a broader group of products without identifying affected versions:
- Security Gateway
- Security Management Server
- Spark Firewall with Site-to-Site or Remote Access VPN
- Spark Firewall without that stated VPN condition
The duplicate Spark Firewall entries leave the product’s exposure unclear. Check Point has not identified which Spark models, firmware versions, or deployment modes are vulnerable. Security Management Server versions are similarly unspecified outside the Quantum branch information.
This gap is particularly relevant to R81.10 users. Two customers running that branch reported that neither a Jumbo Hotfix nor Live Patch was available to them, leaving only the advisory’s mitigation route.
Live Patch is rolling out, but permanent fix builds remain unspecified
Check Point offers two remediation paths through advisories sk1000117 and sk1000118.
The first is Check Point Live Patch, whose rollout began on September 9, 2026. Systems using the service should receive protection automatically as deployment reaches them.
A Check Point employee said Live Patch could be installed over any Jumbo Hotfix level on R81.20, R82.00, and R82.10. Those were the only versions included in that statement. The use of R82.00 there differs from the R82 naming in the affected-version table, and no further clarification was provided.
The second option is to install the latest Jumbo Hotfix for the deployed release once Check Point makes it available. Because the company has not listed the first fixed Take for each branch, administrators should not assume that moving just above the affected thresholds is sufficient without checking the relevant advisory.
Users without an available patch face less certain guidance. One R81.10 customer said the mitigation appeared to require disabling implied VPN rules but did not explain which configuration lines had to be changed. Another asked how to apply the mitigation without disrupting remote users. Neither question received an answer.
Administrators should therefore prioritize Live Patch where supported and monitor sk1000117 and sk1000118 for branch-specific Jumbo Hotfix information. Changes to implied VPN rules should be tested carefully because they could interrupt remote-access or site-to-site connectivity.
Customers report delayed updates and broken advisory links
The initial rollout was not uniform. Five separate customer accounts reported that their gateways remained on Take 17 or Take 18 of the urgent security update package on the announcement day.
One update log showed Take 18 installed on September 1, 2026, with no subsequent package visible. That does not establish that the system was still vulnerable, but it shows why administrators should verify actual patch state rather than assume automatic distribution has completed.
Several customers also said download links in the two security advisories did not work. Check Point staff replied that the links had been tested successfully, although one customer later reported failures in two browsers. The corresponding link in the Live Patch article reportedly remained functional.
Organizations using automatic rollout should confirm that the relevant protection is installed on every gateway and management server. A configured Live Patch service is not the same as a completed deployment.
No exploitation is known, but defenders have no published IOCs
Check Point says it has seen no external exploitation of either vulnerability. The company has not released indicators of compromise, explaining that IOCs apply when an exploit and associated attack activity have been observed.
Consequently, there are no vendor-provided IP addresses, file hashes, process names, log patterns, or network signatures for defenders to search. The absence of IOCs should not be interpreted as proof that an internet-exposed appliance is safe.
It is also unknown whether applying Live Patch or a Jumbo Hotfix would remove access already obtained by an attacker. Patching closes the vulnerable path, but Check Point has not said that remediation performs credential resets, session invalidation, persistence checks, or forensic collection.
The CISA Known Exploited Vulnerabilities status of CVE-2026-85102 and CVE-2026-85103 is not available in the published records. There is therefore no confirmed KEV entry date or federal remediation deadline for either new identifier.
Earlier Check Point flaws were actively exploited
The disclosures follow two earlier Check Point authentication and certificate-validation vulnerabilities that entered CISA’s KEV catalog.
CVE-2026-50751, rated 9.3, affects certificate validation in deprecated IKEv1 Remote Access and Mobile Access workflows. It allows an unauthenticated attacker to bypass password authentication and establish a remote-access VPN connection.
CISA added it to KEV on June 8, 2026, with a remediation deadline of June 11, 2026, for U.S. federal agencies. The vulnerability has been used in ransomware campaigns. CISA directed organizations to apply vendor mitigations, follow applicable BOD 22-01 cloud guidance, or discontinue affected products when mitigation was unavailable.
CVE-2026-16232, rated 9.8, allows an unauthenticated attacker to obtain a SmartConsole application token and authenticate with full administrative privileges. Remote exploitation requires internet access to the Management Server and a configuration that does not restrict Trusted Clients.
CISA added that flaw to KEV on July 22, 2026, setting a federal remediation deadline of July 25, 2026. Check Point acknowledged exploitation affecting a very small number of customers. CISA required vendor mitigations alongside BOD 26-04 risk-based patching and forensic triage guidance.
CVE-2026-85103 again reaches Security Management Server functionality, placing the latest disclosure within a recent series of high-impact Check Point weaknesses rather than an isolated gateway bug. Unlike those earlier cases, however, the two new vulnerabilities currently have no reported exploitation and no actionable IOCs.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-16232Critical9.8An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies
- CVE-2026-85102Critical9.8Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
- CVE-2026-85103Critical9.8A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
- CVE-2026-50751Critical9.3A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
