CVE-2026-85102
CVE-2026-85103
September 10, 2026
·
0
Minutes Read

Check Point Patches Two Critical RCE Bugs in VPN Certificate Handling

Security Advisory
Advisory
September 10, 2026
·
0
Minutes Read

Check Point Patches Two Critical RCE Bugs in VPN Certificate Handling

Security Advisory
Advisory
September 10, 2026
·
0
Minutes Read
Kudelski Security Team
Find out more
table of contents
Share on
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Summary

Check Point has disclosed and patched two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, sharing 9.8 CVSS scores, in the way its firewall and management products handle VPN certificates, both of which can lead to unauthenticated remote code execution. Check Point states both flaws allow RCE only "under specific conditions" that the company has not publicly described. As of September 9, 2026, Check Point has seen no evidence of external exploitation. Fixes are available via Check Point LivePatch (Take 24, automatic rollout began September 9) and the Jumbo Hotfix Accumulator (Take 44 / 126 / 166 depending on version). Version R82.20 is not affected.

Affected Systems and/or Applications

Attribute CVE-2026-85102 CVE-2026-85103
Title Authentication Bypass and RCE in Remote Access and Site-to-Site VPN ASN.1 decoding heap overflow leading to RCE
Affected Products Security Gateway, Check Point Spark Firewall (using Site-to-Site VPN or Remote Access VPN) Security Management Server, Security Gateway, Check Point Spark Firewall
CVSS 9.8 (Critical) 9.8 (Critical)

Affected Versions (both CVEs, identical lists):

  • R81.20, R82, R82.10
  • R81.10.x, R82.00.x (Spark Firewalls)
  • All End-of-Support versions: R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10
  • Equivalently, via the Jumbo Hotfix Accumulator: R82.10 at Take 43 or below, R82 at Take 125 or below, R81.20 at Take 165 or below

Not affected: R82.20

Important scope note for CVE-2026-85103: the flaw resides in certificate processing, not the VPN software blade itself. A Check Point staff member confirmed it could theoretically be triggered in a gateway environment with a disabled VPN, but where VPN certificates are present.

Technical Details

CVE-2026-85102: Certificate trust validation failure during VPN negotiation During the establishment of a VPN session, the gateway fails to properly validate certificate data/trust presented during negotiation. This constitutes an authentication bypass in Remote Access and Site-to-Site VPN flows, allowing an unauthenticated remote attacker to execute arbitrary code on the Security Gateway.

CVE-2026-85103: Heap-based buffer overflow in VPN certificate ASN.1 decoding While decoding the ASN.1 structure of a VPN certificate, a heap overflow can occur under certain circumstances. Pre-authentication memory corruption of this class is a classic route to remote code execution. Notably, the affected decoding flow also impacts the Security Management Server, in addition to gateways and Spark Firewalls.

Neither vulnerability requires authentication; the attacker is remote and unauthenticated. Check Point has not described the precise conditions necessary for successful exploitation at the time of writing.

Mitigation

  1. Patch (strongly preferred):
  • Option 1: Check Point LivePatch (rollout began September 9, 2026) Customers with automatic installation enabled are already protected. The urgent security update is delivered as Take 24 of the respective autoupdate bundles:
Version LivePatch Package
R82.10 BUNDLE_URGENT_SECURITY_UPDATE_R82_10_AUTOUPDATE take 24
R82 BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE take 24
R81.20 BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE take 24
  • Option 2: Jumbo Hotfix Accumulator / build upgrades
Product / Version Fixed in
R82.10 Jumbo Hotfix Accumulator Take 44 or later
R82 Jumbo Hotfix Accumulator Take 126 or later
R81.20 Jumbo Hotfix Accumulator Take 166 or later
Spark Firewalls R82.00.10 Build 2325 or later
Spark Firewalls R81.10.17 Build 4968 or later
  1. Workaround (if immediate patching is not possible):
  • For Site-to-Site VPN: disable the implied rules for VPN and manually define VPN access rules permitting UDP/500 and UDP/4500 only from specific, known peer IP addresses. This restricts which sources can reach the IKE negotiation surface.
  • Note: this mitigation is not applicable to locally managed Spark Firewalls.

What the Cyber Fusion Center is Doing

The CFC is actively monitoring threat intelligence and reports related to CVE-2026-85102 and CVE-2026-85103. This advisory will be updated if required.

References

Related Post