Check Point Patches Critical VPN Vulnerabilities, Warns of Remote Code Execution Risk
A critical-severity vulnerability has been patched by cybersecurity firm Check Point in its gateway and firewall products that utilize virtual private network (VPN) functionality. The flaw, tracked as CVE-2026-85102, affects Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN. A second vulnerability, CVE-2026-85103, impacts the Check Point Security Management Server, Security Gateway, and Spark Firewall.
According to Check Point’s security alert, both vulnerabilities can be exploited without authentication for remote code execution (RCE), a serious risk that could allow attackers to gain unauthorized access to sensitive systems. The company warns that these exploits have a CVSS score of 9.8, indicating their severity. It is worth noting that the exploitation of such high-severity vulnerabilities often requires minimal technical expertise and can be carried out remotely.
The patches, released for versions R82.10, R82, and R81.20 of all products affected by the vulnerabilities, address improper validation of certificate data during VPN negotiation in CVE-2026-85102, as well as a heap overflow in the VPN certificate ASN.1 decoding flow in CVE-2026-85103. To mitigate these risks, Check Point recommends that users manually define VPN rules for Site to Site VPN and disable implied rules for VPN.
For users with locally managed Spark Firewall instances, which are not automatically updated by the recommended patch, it is crucial to apply the latest Jumbo hotfixes as soon as possible to prevent exploitation. Additionally, customers with Check Point LivePatch enabled will receive the patches automatically, ensuring their systems remain up-to-date and secure.
Check Point’s proactive approach in detecting these vulnerabilities internally and issuing timely patches highlights its commitment to maintaining the security of its products and protecting its users’ sensitive information. This incident serves as a reminder for organizations to stay vigilant about patching known vulnerabilities and implementing robust security measures to prevent exploitation by attackers.
In practical terms, this means that IT administrators should promptly apply the latest updates and follow Check Point’s recommended mitigation steps to ensure their systems remain secure against these critical VPN vulnerabilities. By doing so, they can significantly reduce the risk of unauthorized access and protect sensitive data from being compromised.
Source: SecurityWeek — 2026-09-11