Cyber Security

Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks

Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote code execution under specific conditions.

Check Point’s own research team uncovered the flaws, and the company says it has found no evidence of active exploitation or public proof-of-concept code as of this writing.

Check Point VPN Vulnerabilities

CVE-2026-85102 is rooted in improper certificate trust validation during VPN negotiation, tracked under CWE-295. According to Check Point’s advisory sk1000117, the flaw fails to properly validate the trust of a presented certificate, letting an unauthenticated attacker push VPN negotiation far enough to execute arbitrary code on the Security Gateway. This affects both Remote Access VPN and Site-to-Site VPN configurations.

CVE-2026-85103, by contrast, is a heap-based buffer overflow (CWE-122) that occurs while the product parses the ASN.1 structure of a VPN certificate. Detailed in advisory sk1000118, this bug lets a remote attacker trigger the overflow simply by sending a malicious certificate, potentially achieving code execution on both Quantum Security Gateway and Quantum Security Management systems.

The vulnerabilities affect Check Point Security Gateway, Security Management Server, and Spark Firewall deployments across multiple release branches, including R81.20, R82, and R82.10 with Jumbo Hotfix Takes below the newly patched builds, along with several end-of-support versions such as R80.40 and R81. Check Point has confirmed that R82.20 is not affected.

Notably, CVE-2026-85102 primarily impacts Security Gateways engaged in VPN connections, while CVE-2026-85103 spans both gateway and management infrastructure.

Organizations using Check Point Live Patch benefit automatically, since the protective rollout began on September 9, 2026. Administrators without Live Patch enabled must manually install the latest Jumbo Hotfix Accumulator for their branch, specifically R82.10 Take 44 or higher, R82 Take 126 or higher, or R81.20 Take 166 or higher, along with dedicated Spark Firewall builds.

For Site-to-Site VPN deployments that cannot patch immediately, Check Point recommends disabling implied VPN rules and restricting UDP ports 500 and 4500 to known peer IP addresses, though this workaround does not extend to Remote Access VPN, and no interim mitigation exists for locally managed Spark Firewalls.

These newly patched bugs are unrelated to the actively exploited CVE-2026-50751, an IKEv1 authentication bypass tied to Qilin ransomware activity disclosed earlier this year.

Given the critical severity and network-exploitable nature of both new flaws, security teams running Check Point infrastructure should prioritize patching immediately rather than waiting for confirmed in-the-wild exploitation.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago