Check Point has announced fixes for two critical vulnerabilities found in its firewall and management products related to VPN certificate handling. These flaws, if exploited, could potentially enable a remote attacker without authentication to execute arbitrary code, although specific conditions for exploitation remain unspecified by the company.
Details of the Vulnerabilities
The first vulnerability, identified as CVE-2026-85102, affects Check Point’s Security Gateways. It involves improper validation during VPN certificate negotiation, posing risks of unauthorized code execution. The second, CVE-2026-85103, is a heap-based buffer overflow occurring during the decoding of VPN certificate structures, impacting both Security Gateways and the Security Management Server.
Both vulnerabilities have been assigned a CVSS score of 9.8, indicating their critical nature. They affect specific versions of Check Point’s Quantum branches, namely R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, and R81.20 with Jumbo Hotfix Take 165 or below.
Customer Advisory and Response
Check Point disclosed these issues on September 9, immediately rolling out patches. The company reassured that it discovered the flaws internally and found no evidence of them being exploited in real-world attacks. Customers are advised to apply the Check Point Live Patch for automatic protection or the latest available Jumbo Hotfix.
Despite the rollout, some customers reported delays in receiving the updates. Additionally, there were concerns about the mitigation steps for those unable to patch immediately, with some customers seeking clarification on configuration changes needed to deactivate implied rules for VPNs.
Historical Context and Industry Impact
This isn’t the first time Check Point has had to address critical vulnerabilities in its products. Earlier this year, the company patched other significant flaws, including CVE-2026-50751 and CVE-2026-16232, which were reportedly already being exploited. These patches were critical in safeguarding against authentication bypasses within their Remote Access VPN and Security Management systems.
Check Point has yet to release specific indicators of compromise related to these new flaws, as there is no current evidence of active exploitation. The company continues to provide guidance through advisories sk1000117 and sk1000118 for affected products and remediation steps.
As the cybersecurity landscape evolves, it is crucial for organizations using Check Point products to stay updated with the latest patches and advisories to protect their systems from potential threats.
