Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Check Point Addresses Severe VPN Security Flaws

Check Point Addresses Severe VPN Security Flaws

Posted on September 11, 2026 By CWS

Cybersecurity leader Check Point has deployed crucial patches to address two high-risk vulnerabilities identified in its VPN-enabled gateway and firewall products. These vulnerabilities, known as CVE-2026-85102 and CVE-2026-85103, both hold a critical CVSS rating of 9.8, indicating their potential for serious security breaches if left unpatched.

Details of the Vulnerabilities

The vulnerabilities pose a significant risk as they could allow unauthorized remote code execution. CVE-2026-85102 stems from inadequate validation of certificate data during VPN negotiation, while CVE-2026-85103 involves a heap overflow issue in the VPN certificate ASN.1 decoding process. These flaws affect various Check Point products, including the Security Gateway, Spark Firewall, and Security Management Server.

Check Point has released security updates for product versions R82.10, R82, and R81.20. Users are strongly encouraged to install these updates to safeguard their systems against potential exploits.

Mitigation Strategies and Recommendations

For those using Site to Site VPN, Check Point advises disabling implied rules and manually defining VPN access rules specifically for UDP/500 and UDP/4500, targeting specific peer IP addresses. However, this mitigation strategy is not applicable to locally managed Spark Firewall instances.

Customers managing Spark Firewall instances locally are urged to apply the latest Jumbo hotfixes without delay. Those with Check Point LivePatch enabled will receive the necessary patches automatically, ensuring continuous protection against these vulnerabilities.

Discovery and Preventive Measures

Check Point discovered these vulnerabilities internally and confirms that there has been no evidence of them being exploited in real-world scenarios. This proactive approach highlights the company’s commitment to maintaining robust security measures.

Earlier this year, Check Point also alerted its users about two zero-day vulnerabilities, CVE-2026-16232 and CVE-2026-50751, underscoring the ongoing threats facing network security. The swift action to patch these new vulnerabilities further emphasizes the importance of timely updates in preventing cyber threats.

As cyber threats continue to evolve, staying informed about potential security risks and applying necessary patches remain critical components in safeguarding digital infrastructure.

Security Week News Tags:Check Point, CVE, cyber attack, Cybersecurity, data protection, Firewall, IT security, network security, remote code execution, risk management, security management, security patches, security updates, software vulnerabilities, VPN vulnerabilities

Post navigation

Previous Post: Rethinking Security: Focus on Medium Risks
Next Post: Windows 11 Update Disrupts Always On VPN Connections

Related Posts

Industry Reactions to Trump Cybersecurity Executive Order: Feedback Friday Industry Reactions to Trump Cybersecurity Executive Order: Feedback Friday Security Week News
Progress Releases Vital Patches for MOVEit and LoadMaster Progress Releases Vital Patches for MOVEit and LoadMaster Security Week News
Synnovis Confirms Patient Information Stolen in Disruptive Ransomware Attack Synnovis Confirms Patient Information Stolen in Disruptive Ransomware Attack Security Week News
Zero Networks Raises  Million for Microsegmentation Solution Zero Networks Raises $55 Million for Microsegmentation Solution Security Week News
2024 VMware Flaw Now in Attackers’ Crosshairs 2024 VMware Flaw Now in Attackers’ Crosshairs Security Week News
Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows 11 Update Disrupts Always On VPN Connections
  • Check Point Addresses Severe VPN Security Flaws
  • Rethinking Security: Focus on Medium Risks
  • Exploited JFrog Artifactory Vulnerabilities Risk Supply Chains
  • Trezor Users Targeted by Phishing After Brevo Data Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows 11 Update Disrupts Always On VPN Connections
  • Check Point Addresses Severe VPN Security Flaws
  • Rethinking Security: Focus on Medium Risks
  • Exploited JFrog Artifactory Vulnerabilities Risk Supply Chains
  • Trezor Users Targeted by Phishing After Brevo Data Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark