Check Point Software Technologies has announced the resolution of two significant vulnerabilities affecting their VPN products. Identified as CVE-2026-85102 and CVE-2026-85103, these flaws were assessed with a CVSS score of 9.8, indicating their critical nature. Both vulnerabilities could potentially allow unauthorized remote code execution under specific circumstances.
Discovery and Impact
The vulnerabilities were identified by Check Point’s internal research team. At the time of disclosure, there was no evidence to suggest that these vulnerabilities had been actively exploited in the wild, nor was there any public proof-of-concept code available.
CVE-2026-85102 arises from improper validation of certificate trust during VPN negotiation, categorized under CWE-295. This flaw allows attackers to manipulate the VPN negotiation process, eventually leading to arbitrary code execution on the Security Gateway. Both Remote Access VPN and Site-to-Site VPN setups are affected by this issue.
Technical Details and Affected Systems
In contrast, CVE-2026-85103 is a heap-based buffer overflow issue, tracked as CWE-122. It is triggered when a VPN certificate’s ASN.1 structure is incorrectly parsed, potentially enabling a malicious actor to execute code on Quantum Security Gateway and Management systems by sending a crafted certificate.
These security weaknesses impact several Check Point products, including the Security Gateway, Security Management Server, and Spark Firewall, across multiple software versions like R81.20, R82, and R82.10, unless they have been updated with the latest patches. Notably, version R82.20 remains unaffected.
Patch Deployment and Recommendations
Organizations with Check Point Live Patch benefit from automatic updates, which began distribution on September 9, 2026. However, for those without Live Patch, immediate manual installation of the latest Jumbo Hotfix Accumulator is imperative. For R82.10, the recommended Take is 44 or higher, for R82, Take 126 or higher, and for R81.20, Take 166 or higher.
To mitigate risks for Site-to-Site VPNs that cannot be patched promptly, Check Point advises disabling implied VPN rules and limiting UDP ports 500 and 4500 to known peers. Unfortunately, no temporary solution is available for Remote Access VPN or locally managed Spark Firewalls.
Despite the critical nature of these vulnerabilities, they are distinct from the previously exploited CVE-2026-50751, which was linked to Qilin ransomware activities.
Organizations utilizing Check Point’s infrastructure are strongly advised to prioritize these updates to safeguard against potential threats, even in the absence of confirmed exploitation cases.
