Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Cisco ASA, FTD Critical Flaw CVE-2024-20353 Lets Attackers Gain Root Access
September 10, 2026
Passkey Phishing Attacks Hijack Microsoft 365 Accounts, Steal Cloud Data
September 10, 2026
Critical Check Point VPN Vulnerabilities Allow RCE Attacks
September 10, 2026
Home/CyberSecurity News/Critical Check Point VPN Vulnerabilities Allow RCE Attacks
CyberSecurity News

Critical Check Point VPN Vulnerabilities Allow RCE Attacks

Key Takeaways Check Point has released patches for two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103. Both flaws carry a CVSS score of 9.8 and could enable unauthenticated remote...

David kimber
David kimber
September 10, 2026 3 Min Read
2 0

Key Takeaways

  • Check Point has released patches for two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103.
  • Both flaws carry a CVSS score of 9.8 and could enable unauthenticated remote code execution.
  • The vulnerabilities affect various Check Point Security Gateway, Security Management Server, and Spark Firewall versions.
  • While no active exploitation has been detected, immediate patching is strongly recommended.

Check Point Software has addressed two severe vulnerabilities within its VPN products, identified as CVE-2026-85102 and CVE-2026-85103. Both security flaws have been assigned a maximum CVSS score of 9.8, indicating their critical nature, and possess the potential for unauthenticated remote code execution under specific circumstances.

Table Of Content

  • Key Takeaways
  • Check Point VPN Vulnerabilities Detailed
  • CVE-2026-85102: Improper Certificate Trust Validation
  • CVE-2026-85103: Heap-Based Buffer Overflow
  • What You Should Do

The company’s internal research team discovered these issues. As of this report, Check Point states there is no evidence of these vulnerabilities being actively exploited in the wild, nor has any public proof-of-concept code been released.

Check Point VPN Vulnerabilities Detailed

CVE-2026-85102: Improper Certificate Trust Validation

This vulnerability stems from a deficiency in how VPN connections validate certificate trust, categorized under CWE-295. According to Check Point’s advisory sk1000117, the system fails to adequately verify the authenticity of a presented certificate during VPN negotiation. This allows an attacker, without prior authentication, to advance the VPN negotiation process sufficiently to execute arbitrary code on the Security Gateway. Both Remote Access VPN and Site-to-Site VPN configurations are susceptible to this flaw.

CVE-2026-85103: Heap-Based Buffer Overflow

In contrast, CVE-2026-85103 is a heap-based buffer overflow, classified as CWE-122. This vulnerability occurs when the product processes the ASN.1 structure of a VPN certificate. As detailed in advisory sk1000118, a remote attacker can trigger this overflow by sending a specially crafted malicious certificate. This could lead to code execution on both Quantum Security Gateway and Quantum Security Management systems.

These vulnerabilities impact a range of Check Point deployments, including Security Gateway, Security Management Server, and Spark Firewall, across several release branches. Affected versions include R81.20, R82, and R82.10 with Jumbo Hotfix Takes below the recently patched builds. Several end-of-support versions, such as R80.40 and R81, are also vulnerable. Check Point has confirmed that R82.20 is not affected by these issues.

It is important to note the scope difference: CVE-2026-85102 primarily affects Security Gateways involved in VPN connections, whereas CVE-2026-85103 has a broader impact, extending to both gateway and management infrastructure components.

For organizations using Check Point Live Patch, protection against these vulnerabilities was automatically rolled out starting September 9, 2026. However, administrators who do not have Live Patch enabled must manually install the latest Jumbo Hotfix Accumulator for their specific branch. This includes R82.10 Take 44 or higher, R82 Take 126 or higher, or R81.20 Take 166 or higher, in addition to dedicated Spark Firewall builds.

For Site-to-Site VPN deployments unable to apply patches immediately, Check Point suggests a temporary mitigation: disabling implied VPN rules and restricting UDP ports 500 and 4500 to only known peer IP addresses. This workaround, however, is not applicable to Remote Access VPNs, and no interim mitigation is available for locally managed Spark Firewalls.

It is crucial to distinguish these newly disclosed vulnerabilities from CVE-2026-50751, an IKEv1 authentication bypass linked to Qilin ransomware activity that was disclosed and actively exploited earlier this year.

What You Should Do

  • Prioritize Patching: Given the critical severity and network-exploitable nature of both flaws, security teams managing Check Point infrastructure should apply the necessary patches immediately. Do not wait for confirmed in-the-wild exploitation.
  • Verify Live Patch Status: If you utilize Check Point Live Patch, confirm that the automatic updates were successfully applied.
  • Manual Updates: For systems without Live Patch, download and install the latest Jumbo Hotfix Accumulator appropriate for your specific product branch and version (e.g., R82.10 Take 44+, R82 Take 126+, R81.20 Take 166+).
  • Apply Workarounds (Site-to-Site VPN Only): If immediate patching for Site-to-Site VPN is not feasible, implement the recommended workarounds: disable implied VPN rules and restrict UDP ports 500 and 4500 to known peer IP addresses. Be aware that this does not mitigate risks for Remote Access VPN or locally managed Spark Firewalls.
  • Stay Informed: Continue monitoring Check Point advisories and security news for any further updates or emerging threats.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchransomwareSecurity

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

New Attack Steals Data via AI Workflows, No Jailbreak Needed

Next Post

Passkey Phishing Attacks Hijack Microsoft 365 Accounts, Steal Cloud Data

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Palo Alto PAN-OS Critical Vulnerability Lets Attackers Execute Code as Root
September 10, 2026
OpenSSL 4.1.0 Alpha1 Released With DTLS 1.3 and Faster Post-Quantum Crypto
September 10, 2026
Critical Active Directory Flaw Lets Attackers Impersonate Domain Controllers
September 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us