Critical VPN Vulnerabilities Exposed in Check Point Products
Check Point, a leading cybersecurity firm, has just released patches for two critical-severity vulnerabilities in its gateway and firewall products that use virtual private network (VPN) functionality. The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, could be exploited without authentication to execute malicious code on affected systems. According to Check Point, both vulnerabilities have a CVSS score of 9.8, making them extremely severe.
The two vulnerabilities affect different products in the Check Point lineup: CVE-2026-85102 impacts Security Gateway and Check Point Spark Firewall using Site-to-Site VPN or Remote Access VPN, while CVE-2026-85103 affects the Check Point Security Management Server, Security Gateway, and Spark Firewall. The company has released security updates for versions R82.10, R82, and R81.20 of all products.
To mitigate these vulnerabilities, Check Point recommends manually defining VPN rules, particularly for Site-to-Site VPN. For this specific scenario, the company advises disabling implied rules for VPN and manually configuring access for UDP/500 and UDP/4500 port numbers from specific peer IP addresses. However, it’s essential to note that this mitigation does not apply to locally managed Spark Firewall instances.
For users with locally managed instances, Check Point recommends applying the latest Jumbo hotfixes as soon as possible. Those with Check Point LivePatch enabled will receive the patches automatically. It’s reassuring to know that both vulnerabilities were discovered internally by Check Point and that there is no evidence of exploitation in the wild so far.
The discovery of these critical vulnerabilities follows a summer warning from Check Point regarding the exploitation of two zero-day vulnerabilities, including CVE-2026-16232 and CVE-2026-50751. This incident highlights the importance of regularly updating security products and implementing robust mitigation strategies to prevent potential attacks.
As a result of this vulnerability exposure, it’s crucial for users to prioritize patching their Check Point products as soon as possible. This includes not only applying the latest security updates but also manually configuring VPN rules to minimize the risk of exploitation. By taking proactive steps to secure their systems, organizations can significantly reduce the likelihood of falling victim to these types of vulnerabilities.
In conclusion, the discovery and patch release for these critical VPN vulnerabilities serve as a reminder of the ongoing threats in the cybersecurity landscape. It’s essential for users to stay vigilant, regularly update their security products, and implement robust mitigation strategies to protect against potential attacks.
Source: SecurityWeek — 2026-09-11