Check Point fixes critical VPN RCE flaws in gateways

Check Point patched two critical VPN flaws, CVE-2026-85102 and CVE-2026-85103, that allow unauthenticated remote code execution in Security Gateway, Spark Firewall and Security Management Server.

Check Point released patches this week for two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, that could allow unauthenticated remote code execution in Security Gateway, Check Point Spark Firewall and Security Management Server.

Both flaws carry a 9.8 score on the CVSS scale and can be triggered without authentication. CVE-2026-85102 results from improper validation of certificate data during VPN negotiation. CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoding process. Because both vulnerabilities affect certificate processing, organizations should treat encryption key management as part of securing the entire certificate lifecycle.

The vendor identified the affected products and configurations. CVE-2026-85102 impacts Security Gateway and Spark Firewall when configured for Site-to-Site VPN or Remote Access VPN. CVE-2026-85103 affects Security Management Server in addition to Security Gateway and Spark Firewall. Security updates are available for versions R82.10, R82 and R81.20.

Check Point provided mitigation steps for administrators. For Site-to-Site VPN, it recommends disabling implied VPN rules and manually defining VPN access for UDP/500 and UDP/4500 restricted to the specific peer IP addresses. That manual rule mitigation does not apply to locally managed Spark Firewall instances; those devices should receive the latest Jumbo hotfixes. Customers with Check Point LivePatch enabled will receive the fixes automatically.

The company reported it discovered both vulnerabilities internally and found no evidence of exploitation in the wild. The advisory follows earlier warnings this summer about active exploitation of other zero-day flaws, including CVE-2026-16232 and CVE-2026-50751.

Network and security teams running affected Check Point products should verify their software versions, confirm whether LivePatch is active, apply the released updates or hotfixes, and implement the recommended manual VPN rule changes where applicable.

Articles by this author