HomeTopics 4Network SecurityCheck Point Warns of Two Critical VPN Flaws That Could Enable Unauthenticated...

Check Point Warns of Two Critical VPN Flaws That Could Enable Unauthenticated Remote Code Execution

Date:

Related stories

Android September 2026 Security Bulletin Fixes Critical Remote-Code-Execution Flaws

Google’s latest Android security update addresses critical vulnerabilities in...

VMware Workstation and Fusion Hit by Critical Host-Code Execution Flaws, Patch to 26H1u1 Now

The vulnerabilities, tracked as CVE-2026-59346 and CVE-2026-59347, affect VMware...

SonicWall Urges Immediate Patching as Actively Exploited SMA1000 Flaws Put Remote Access Appliances at Risk

The vulnerabilities, tracked as CVE-2026-83548 and CVE-2026-83549, affect SonicWall...

AWS Root Accounts Targeted in Password-Spraying Campaign Across More Than 150 Organizations

Attackers are increasingly targeting the most powerful identities in...
spot_imgspot_imgspot_imgspot_img

Two newly disclosed vulnerabilities affecting Check Point VPN infrastructure carry a CVSS score of 9.8. Check Point says there is currently no indication of active exploitation, but organizations are being urged to patch as soon as possible.

Check Point has issued an urgent security advisory for two critical vulnerabilities affecting its VPN infrastructure, warning that attackers could potentially achieve remote code execution without authentication under specific conditions.

The vulnerabilities, tracked as CVE-2026-85102 and CVE-2026-85103, were discovered internally by Check Point’s research team. The company says it has no indication that either vulnerability is being actively exploited in the wild.

That does not make the disclosure low-risk.

Both vulnerabilities have been rated 9.8 out of 10 (Critical) under CVSS 3.1, with network-based exploitation possible without requiring user interaction or prior privileges. The combination makes internet-facing VPN infrastructure a particularly important asset for security teams to review immediately.

What Check Point disclosed

The first vulnerability, CVE-2026-85102, involves improper certificate validation during VPN negotiation. According to the CVE record, an unauthenticated remote attacker could potentially execute arbitrary code on an affected Check Point Quantum Security Gateway.

The second, CVE-2026-85103, is a heap-based buffer overflow in VPN certificate ASN.1 decoding. Under the described conditions, an unauthenticated remote attacker could also potentially execute arbitrary code on affected Quantum Security Gateway and Quantum Security Management systems.

In simple terms, both flaws sit in components involved in handling VPN connections and certificates. If successfully exploited, the consequences could go well beyond a failed login or denial-of-service condition: remote code execution can give an attacker the ability to run commands on the affected system with potentially serious consequences for confidentiality, integrity and availability.

The CVE records assign both vulnerabilities a CVSS 3.1 score of 9.8, with an attack vector of network, low attack complexity, no privileges required and no user interaction required.

Which Check Point products and versions are affected?

The published CVE information identifies the following versions as affected:

  • R82.10 with Jumbo Hotfix Take 43 or earlier
  • R82 with Jumbo Hotfix Take 125 or earlier
  • R81.20 with Jumbo Hotfix Take 165 or earlier

CVE-2026-85102 is listed against Quantum Security Gateway, while CVE-2026-85103 affects both Quantum Security Gateway and Quantum Security Management.

Check Point has already begun addressing the vulnerabilities through its Jumbo Hotfix releases. Its R82 Take 126 documentation, for example, identifies the fix for CVE-2026-85103, while R82.10 Take 44 includes the corresponding remediation for that vulnerability.

Organizations should therefore avoid relying on the CVE number alone. Security teams need to verify the exact Check Point product, software version and Jumbo Hotfix Take installed in their environment, then compare it with Check Point’s current remediation guidance.

Check Point recommends immediate remediation

In its CheckMates security advisory, Check Point recommends installing the latest available Jumbo Hotfix for the deployed version as soon as it becomes available.

The company also says customers using Check Point Live Patch will be automatically protected as the rollout begins on September 9, 2026. Customers not using Live Patch are directed to Check Point’s guidance on the service and the applicable security advisories.

The two official security advisories are:

  • CVE-2026-85102 — Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN — sk1000117
  • CVE-2026-85103 — ASN.1 Decoding Heap Overflow Leading to Remote Code Execution — sk1000118

Security teams should use the vendor advisories as the authoritative source for product-specific remediation rather than applying generic workarounds that have not been confirmed by Check Point.

Why VPN vulnerabilities remain particularly dangerous

VPN gateways occupy an unusual position in enterprise networks.

They are designed to sit at the edge of the organization and accept connections from remote users, offices, partners and other networks. That makes them useful for legitimate access but also makes them attractive targets for attackers.

A vulnerability that allows an unauthenticated attacker to execute code on an internet-facing VPN appliance can potentially provide a foothold before conventional identity controls even have a chance to stop the intrusion.

This is not a theoretical concern limited to Check Point.

Cybercory has previously reported on attackers exploiting VPN and remote-access infrastructure, including the exploitation of a Palo Alto Networks VPN vulnerability linked to Qilin ransomware intrusions and the active exploitation of a WatchGuard Firebox VPN vulnerability. Those incidents demonstrated how weaknesses at the network perimeter can become the starting point for much larger compromises.

The lesson is straightforward: a VPN appliance should be treated as a high-value security asset, not simply another network device.

For organizations reviewing the basics of VPN security, Cybercory’s guide, What Is VPN? Tunneling Through the Web: A Comprehensive Guide, provides additional background on how VPN technology works.

No active exploitation reported but don’t wait

One of the most important details in Check Point’s announcement is what the company has not reported.

Check Point says the vulnerabilities were discovered internally and that it has no indication of active exploitation. The current CVE enrichment from CISA also records exploitation as “none.”

That distinction matters.

A vulnerability can be critical without being actively exploited. Once technical details become publicly available, however, defenders should assume that attackers will study the disclosure and attempt to reproduce the vulnerability.

For internet-facing infrastructure, the window between disclosure and exploitation can sometimes be short.

Security teams should therefore avoid waiting for evidence of an attack before beginning remediation.

Why this matters for the Middle East and Africa

The issue is global, but it carries particular relevance for organizations across the Middle East and Africa, where VPN and remote-access infrastructure supports distributed workforces, regional offices, cloud environments, managed services and cross-border operations.

Financial institutions, government agencies, telecommunications companies, energy operators, healthcare organizations and large enterprises can all rely heavily on perimeter security infrastructure.

For organizations operating across several countries, the challenge can be even greater. A single security appliance may provide remote access to employees, contractors, administrators or partners across multiple locations.

That makes accurate asset inventory essential.

Security leaders should know not only whether their organization uses Check Point, but which products are deployed, which versions they run, which systems are exposed to the internet, who can access them and whether the latest security fixes have actually been installed.

Recent Cybercory reporting on SonicWall and MikroTik vulnerabilities has highlighted the same broader issue: internet-facing network infrastructure remains an attractive target and must be included in continuous vulnerability management rather than treated as a one-time patching exercise.

10 actions security teams should take now

1. Identify every affected Check Point deployment

Build or update an inventory of Check Point Quantum Security Gateway and Quantum Security Management systems, including their exact software versions and Jumbo Hotfix Take levels.

2. Verify whether your systems are affected

Compare every deployment against the versions listed in Check Point’s official advisories for CVE-2026-85102 and CVE-2026-85103.

Do not rely on assumptions based on product family or installation date.

3. Install the appropriate Jumbo Hotfix

Apply the latest applicable security update for your deployed Check Point version as soon as operationally possible.

Where possible, prioritize internet-facing VPN gateways first.

4. Use Check Point Live Patch where appropriate

Organizations using Check Point Live Patch should verify that protection has been applied successfully and confirm coverage through their normal administrative and audit processes.

5. Restrict unnecessary VPN exposure

Review which interfaces and services are reachable from the public internet.

Where business requirements allow, restrict VPN access to approved networks, users and devices rather than exposing unnecessary services.

6. Review VPN and gateway logs

Look for unusual authentication attempts, unexpected VPN connections, abnormal certificate activity, suspicious source addresses or other behavior that began around the period of potential exposure.

A lack of known exploitation does not eliminate the value of retrospective investigation.

7. Monitor for post-compromise activity

Because the vulnerabilities could potentially lead to remote code execution, security teams should look beyond the VPN device itself.

Review authentication systems, privileged accounts, management infrastructure and internal network activity for signs of follow-on activity.

8. Strengthen administrative access

Protect management interfaces with strong access controls and multi-factor authentication (MFA) where supported.

Administrative access should be limited to authorized personnel and trusted management networks.

9. Prepare for the possibility of compromise

If suspicious activity is identified, isolate affected systems where operationally possible, preserve logs and forensic evidence, and activate the organization’s incident-response process.

Do not immediately rebuild or wipe a potentially compromised device before collecting evidence unless there is an urgent operational or safety reason to do so.

10. Train the teams responsible for perimeter security

Patching is only one part of the defense.

Network administrators, SOC analysts and incident-response teams should understand how VPN infrastructure fits into the organization’s attack surface and how to recognize suspicious remote-access activity.

Organizations looking to strengthen their broader cybersecurity, vulnerability management, security awareness and technical training can explore Saintynet Cybersecurity and its professional cybersecurity training and services.

The bigger picture

The disclosure of CVE-2026-85102 and CVE-2026-85103 is another reminder that attackers do not need to begin with a phishing email or a compromised employee account.

Sometimes the first target is the device designed to let legitimate users into the network.

That is why VPN gateways, firewalls and other internet-facing security appliances deserve the same level of attention as servers, endpoints and identity systems. They should be continuously inventoried, patched, monitored and included in incident-response exercises.

For now, Check Point says there is no indication that these two vulnerabilities are being actively exploited. But with both vulnerabilities rated critical and capable, under specific conditions, of enabling unauthenticated remote code execution, organizations running affected versions should not wait for an incident to force the issue.

Patch the gateway. Verify the fix. Review the logs. And treat the VPN perimeter as a critical part of the organization’s security architecture.

Source: Check Point Security Advisory / CheckMates; CVE records for CVE-2026-85102 and CVE-2026-85103.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img