[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYZ1fhoUQ63uWn77pxqgQFQRmDniHYJbwavWDGiiEwAc":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"88924979-502f-47c7-b3e6-922dd53461f8","Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE","check-point-discloses-two-9-8-rated-vpn-certificate-flaws-enabling-unauthenticat-33af29","Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only \"under specific conditions\" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security","Check Point has patched two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in its firewall and management products that could allow unauthenticated remote attackers to execute code. Both flaws have a CVSS score of 9.8 and affect specific versions of Check Point's Quantum Security Gateways and Management Servers. While Check Point states it discovered the flaws internally and has no indication of active exploitation, customers are advised to apply fixes via Live Patch or Jumbo Hotfix.","Check Point discloses two critical VPN certificate flaws with CVSS 9.8, enabling unauthenticated RCE.","Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE Swati KhandelwalSep 10, 2026Vulnerability \u002F Network Security Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only \"under specific conditions\" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security Management Server, the console used to configure them. Check Point disclosed the flaws on September 9 in a notice to its customer community, and began delivering fixes the same day. The company says it found both itself and has no indication that either has been used in an attack. The first flaw, CVE-2026-85102, is a failure to properly validate certificate trust during VPN negotiation. Its CVE record says an unauthenticated remote attacker may be able to run code on the Security Gateway. The second, CVE-2026-85103, is a heap-based buffer overflow that happens while the product decodes the ASN.1 structure of a VPN certificate. Its record says an unauthenticated remote attacker may be able to run code on Quantum Security Management and Quantum Security Gateway systems. Both records carry a CVSS score of 9.8. Check Point assigned the identifiers and the scores itself. The two records give the same affected list: R82.10 with Jumbo Hotfix Take 43 or below R82 with Jumbo Hotfix Take 125 or below R81.20 with Jumbo Hotfix Take 165 or below Those are the versions the records mark as affected, not the versions that contain the fix. The list covers three Quantum branches and gives no version information for anything else. An advisory from the Canadian Center for Cyber Security, published the same evening, lists a broader set of products but no versions at all. It lists Security Gateway, Security Management Server, and Spark Firewall, Check Point's small-business line. Spark appears twice, once for deployments using Site-to-Site or Remote Access VPN and once without that condition. In the same community thread, a Check Point staff member was asked whether gateways with the VPN software blade turned off are affected by CVE-2026-85103. The staff member replied that the issue is about certificate processing, so it could, in theory, be triggered in an environment without a VPN but with VPN certificates present. Check Point gave customers two routes to the fix. The first is Check Point Live Patch. The company says customers using it are protected automatically as the rollout begins, which started on September 9. A Check Point employee said in the thread that it can be installed on top of any Jumbo Hotfix level in R81.20, R82.00 and R82.10, and named only those three versions. The second is the Jumbo Hotfix. Check Point told customers to install the latest one for their deployed version once it became available. If You Cannot Patch Yet Two customers said in the thread that they are running R81.10 and will not be moving off it for weeks. One of them said no Jumbo Hotfix and no Live Patch was available for that branch, leaving mitigation as the only option. The same customer described the advisory's mitigation as turning off implied rules for VPN, called it too vague to act on, and asked which configuration lines to comment out. The other asked how to apply the mitigation without affecting remote users. Neither question had an answer in the thread. Several customers also said the automatic rollout had not reached them. Five separate accounts reported gateways were still on Take 18 or Take 17 of the urgent security update package on the day of the announcement; one of them posted an update log showing Take 18 installed on September 1 and nothing since. Several customers reported that download links in the two advisories did not work for them, and a Check Point staff member replied that the links had been checked and were working. One customer said afterward that the advisory links still failed in two browsers, while the link in the Live Patch article worked. In June and July, Check Point patched critical flaws in these products that it said were already being exploited when it announced them. June's was CVE-2026-50751, an authentication bypass in Remote Access VPN and Mobile Access certificate validation. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog on June 8. July's was CVE-2026-16232, a SmartConsole authentication bypass, which CISA added to the same catalog on the day it was disclosed. It was one of three flaws Check Point patched that month, two of which affected the Security Management Server, the same component CVE-2026-85103 reaches. Check Point has not published indicators of compromise for either of the new flaws. Asked in the thread whether logs would show attempts to exploit them, a staff member said the company had seen no evidence of external exploitation, and that indicators of compromise only apply to exploits that already exist. Neither Check Point's notice nor any public record reviewed for this article states which Spark or Security Management versions are affected, which builds contain the fix, or what specific conditions the company says the flaws require. Nothing in that material addresses whether installing the fix removes access an attacker may already have obtained. Check Point's advisories sk1000117 and sk1000118 are the documents it points customers to for affected products, mitigation guidance, and remediation steps. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Check Point, network security, Vulnerability ⚡ Top Stories This Week Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon Fake Software Installers Disable Windows Update and Weaken Microsoft Defender Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another ⭐ Featured Resources Get ","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fcheck-point-discloses-two-98-rated-vpn.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjyc0Kqar7_6N4y9ymGxw8ukQCQbqQ_pGCfnoXYMBZoNZK1w3ljkO26S_rhVhJaIVcx8rcEK95njKyaYj5g63VByKh8ncf_s84nUBWoyEbWZH6uaLYjnu5fNt_TC9wz-r6P_RTJgZ83Z5wmurzSb9_lHVfV1t9STts4WCZr18AH-3XRHTn5pj15uURIM-0\u002Fs1600\u002Fcheckpoint.jpg","2026-09-10T11:45:05+00:00","2026-09-10T14:00:34.037815+00:00",9,[18,21,24,26,28,30],{"name":19,"type":20},"Check Point","vendor",{"name":22,"type":23},"Security Gateway","product",{"name":25,"type":23},"Security Management Server",{"name":27,"type":23},"Spark Firewall",{"name":29,"type":23},"Quantum Security Gateway",{"name":31,"type":23},"Quantum Security Management","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,40],{"category":39},{"id":32,"icon":34,"name":35,"slug":36},{"category":41},{"id":42,"icon":34,"name":43,"slug":44},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[46,50],{"type":47,"value":48,"context":49},"cve","CVE-2026-85102","Failure to properly validate certificate trust during VPN negotiation",{"type":47,"value":51,"context":52},"CVE-2026-85103","Heap-based buffer overflow during ASN.1 decoding of VPN certificates"]