Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: security-gateway (1 article)Clear

Check Point patches two critical VPN certificate flaws enabling unauthenticated code execution

Check Point patched two critical flaws in how its firewall and management products handle VPN certificates, each scored 9.8, that could let an unauthenticated remote attacker run code. CVE-2026-85102 is improper certificate-trust validation during VPN negotiation that can lead to code execution on the Security Gateway. CVE-2026-85103 is a heap overflow while decoding a certificate's structure, affecting both the gateway and the management server. Notably, because the second flaw is about certificate processing, Check Point says it could be triggered even where VPN is not running, so management servers need the fix regardless. Check Point found the issues internally and reports no exploitation yet, though its products were attacked twice this year.

Check
Apply Check Point's Live Patch or the latest Jumbo Hotfix to affected gateways and management servers now, and patch management servers even with the VPN blade off, since certificate processing stays reachable.
Affected
Organizations running affected Check Point Quantum Security Gateway and Management systems (CVE-2026-85102, CVE-2026-85103); an unauthenticated attacker could execute code through VPN certificate handling, and management servers are affected without VPN in use.
Fix
Patch gateways and management servers promptly, confirm Live Patch installed, restrict who can reach these devices, monitor for anomalous certificate-related activity, and treat security infrastructure as a repeatedly targeted asset.