Check Point Patches Two Critical RCE Bugs in VPN Certificate Handling
Check Point Patches Two Critical RCE Bugs in VPN Certificate Handling
Summary
Check Point has disclosed and patched two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, sharing 9.8 CVSS scores, in the way its firewall and management products handle VPN certificates, both of which can lead to unauthenticated remote code execution. Check Point states both flaws allow RCE only "under specific conditions" that the company has not publicly described. As of September 9, 2026, Check Point has seen no evidence of external exploitation. Fixes are available via Check Point LivePatch (Take 24, automatic rollout began September 9) and the Jumbo Hotfix Accumulator (Take 44 / 126 / 166 depending on version). Version R82.20 is not affected.
Affected Systems and/or Applications
Affected Versions (both CVEs, identical lists):
- R81.20, R82, R82.10
- R81.10.x, R82.00.x (Spark Firewalls)
- All End-of-Support versions: R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10
- Equivalently, via the Jumbo Hotfix Accumulator: R82.10 at Take 43 or below, R82 at Take 125 or below, R81.20 at Take 165 or below
Not affected: R82.20
Important scope note for CVE-2026-85103: the flaw resides in certificate processing, not the VPN software blade itself. A Check Point staff member confirmed it could theoretically be triggered in a gateway environment with a disabled VPN, but where VPN certificates are present.
Technical Details
CVE-2026-85102: Certificate trust validation failure during VPN negotiation During the establishment of a VPN session, the gateway fails to properly validate certificate data/trust presented during negotiation. This constitutes an authentication bypass in Remote Access and Site-to-Site VPN flows, allowing an unauthenticated remote attacker to execute arbitrary code on the Security Gateway.
CVE-2026-85103: Heap-based buffer overflow in VPN certificate ASN.1 decoding While decoding the ASN.1 structure of a VPN certificate, a heap overflow can occur under certain circumstances. Pre-authentication memory corruption of this class is a classic route to remote code execution. Notably, the affected decoding flow also impacts the Security Management Server, in addition to gateways and Spark Firewalls.
Neither vulnerability requires authentication; the attacker is remote and unauthenticated. Check Point has not described the precise conditions necessary for successful exploitation at the time of writing.
Mitigation
- Patch (strongly preferred):
- Option 1: Check Point LivePatch (rollout began September 9, 2026) Customers with automatic installation enabled are already protected. The urgent security update is delivered as Take 24 of the respective autoupdate bundles:
- Option 2: Jumbo Hotfix Accumulator / build upgrades
- Workaround (if immediate patching is not possible):
- For Site-to-Site VPN: disable the implied rules for VPN and manually define VPN access rules permitting UDP/500 and UDP/4500 only from specific, known peer IP addresses. This restricts which sources can reach the IKE negotiation surface.
- Note: this mitigation is not applicable to locally managed Spark Firewalls.
What the Cyber Fusion Center is Doing
The CFC is actively monitoring threat intelligence and reports related to CVE-2026-85102 and CVE-2026-85103. This advisory will be updated if required.
References
- The Hacker News — Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
- Check Point SK1000117 — CVE-2026-85102: Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN
- Check Point SK1000118 — CVE-2026-85103: ASN.1 decoding heap overflow leading to remote code execution
- Solved: - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 - Check Point CheckMates
.webp)

.avif)


.webp)

