Check Point has released security updates for two critical vulnerabilities affecting its VPN infrastructure that could allow unauthenticated remote attackers to execute arbitrary code on vulnerable systems.
Tracked as CVE-2026-85102 and CVE-2026-85103, both vulnerabilities carry a CVSS score of 9.8 and can be reached remotely without valid credentials or user interaction.
Check Point says the vulnerabilities were discovered internally and that it has no indication they have been actively exploited. However, the Dutch National Cyber Security Centre (NCSC) has assessed both the likelihood of exploitation and the potential impact as high and expects exploitation attempts to occur soon.
Vulnerability Overview
| CVE | Vulnerability | CVSS | Potential Impact |
| CVE-2026-85102 | Improper certificate validation during VPN negotiation | 9.8 Critical | Unauthenticated remote code execution on Security Gateway |
| CVE-2026-85103 | Heap-based buffer overflow during VPN certificate ASN.1 decoding | 9.8 Critical | Unauthenticated remote code execution on Security Gateway and Security Management systems |
CVE-2026-85102: Improper Certificate Validation During VPN Negotiation
CVE-2026-85102 is an improper certificate validation vulnerability, classified as CWE-295, affecting certificate processing during VPN negotiation.
According to Check Point’s CVE record, improper certificate trust validation can allow an unauthenticated remote attacker to execute arbitrary code on an affected Quantum Security Gateway.
The vulnerability affects deployments using Check Point VPN functionality, including Remote Access VPN and Site-to-Site VPN.
The attack occurs before normal authentication controls can provide meaningful protection. An attacker able to reach the vulnerable VPN service may therefore attempt exploitation without first compromising a user account or obtaining valid VPN credentials.
This is especially significant for internet-facing gateways because VPN infrastructure is intentionally exposed to remote users or external peers.
Check Point’s public vulnerability data identifies the following supported branches as vulnerable:
- R82.10 with Jumbo Hotfix Take 43 or earlier
- R82 with Jumbo Hotfix Take 125 or earlier
- R81.20 with Jumbo Hotfix Take 165 or earlier
The vulnerability was fixed beginning with R82.10 Take 44, R82 Take 126, and R81.20 Take 166.
CVE-2026-85103: ASN.1 Certificate Decoding Heap Overflow
CVE-2026-85103 is a separate vulnerability involving a heap-based buffer overflow, classified as CWE-122, in the processing of ASN.1-encoded VPN certificate data.
A specially crafted certificate processed by the vulnerable decoding functionality may corrupt heap memory and potentially allow an unauthenticated attacker to execute arbitrary code.
The vulnerability affects both Quantum Security Gateway and Quantum Security Management systems.
This gives CVE-2026-85103 a somewhat broader impact surface than CVE-2026-85102 because Security Management infrastructure may also be affected.
Successful exploitation of either vulnerability could potentially give an attacker control of a security appliance positioned at a highly trusted point in the network.
Compromise of an edge security gateway could create opportunities for credential theft, traffic interception, persistence, lateral movement, or further attacks against internal infrastructure.
Exploitation Status
Check Point states that both vulnerabilities were discovered internally and that it has found no indication of active exploitation.
However, defenders should not interpret the absence of known exploitation as an indication that patching can be delayed.
The Dutch NCSC issued an alert on September 10 stating that it considers both the probability of exploitation and the potential impact to be high and expects exploitation attempts to appear soon.
Why VPN Appliances Are High-Value Targets
VPN gateways and other perimeter security appliances remain attractive targets because compromising one can provide attackers with a direct foothold at the edge of an organization’s trusted network.
Check Point infrastructure has already faced significant exploitation activity during 2026.
Earlier this year, CVE-2026-50751, a separate Check Point VPN authentication bypass vulnerability, was exploited in attacks, including post-compromise activity linked to a Qilin ransomware affiliate.
That vulnerability is unrelated to CVE-2026-85102 and CVE-2026-85103, but the incident demonstrates the interest threat actors have in vulnerabilities affecting enterprise VPN infrastructure.
Organizations should therefore treat the newly disclosed vulnerabilities as an urgent exposure-management issue rather than waiting for exploitation to be confirmed.
Affected Products
CERT-EU reports that affected deployments include Check Point Security Gateway, Security Management Server, and Spark Firewall products across several release branches.
Affected versions include:
- R81.20
- R82
- R82.10
- R81.10.x
- R82.00.x
- End-of-support R80, R80.10, R80.20, R80.30 and R80.40
- End-of-support R81 and R81.10
The exact affected component depends on the vulnerability and configuration. CVE-2026-85102 primarily affects Security Gateways using Remote Access VPN or Site-to-Site VPN, while CVE-2026-85103 also affects Security Management systems.
Check Point R82.20 is not affected by the vulnerabilities.
Available Security Updates
Check Point released fixes on September 9, 2026.
Organizations using supported branches should upgrade to at least:
| Product branch | Fixed release |
| R82.10 | Jumbo Hotfix Accumulator Take 44 or later |
| R82 | Jumbo Hotfix Accumulator Take 126 or later |
| R81.20 | Jumbo Hotfix Accumulator Take 166 or later |
| Spark R82.00 | R82.00.10 Build 2325 or later |
| Spark R81.10 | R81.10.17 Build 4968 or later |
Check Point’s own Jumbo Hotfix release documentation confirms that CVE-2026-85102 and CVE-2026-85103 are resolved in R82.10 Take 44, R82 Take 126 and R81.20 Take 166.
Check Point has also released LivePatch Take 24 for supported R81.20, R82 and R82.10 deployments.
Customers with automatic Check Point LivePatch installation enabled should receive protection automatically, but administrators should verify that the update has successfully been installed rather than assuming deployment completed.
End-of-support branches should be migrated to a supported release because permanent fixes may not be available for older versions.
Temporary Mitigation for Site-to-Site VPN
Where immediate patching is not possible, Check Point recommends reducing exposure for Site-to-Site VPN deployments.
Administrators can disable implied VPN rules and manually define access to:
UDP/500
and:
UDP/4500
only for the IP addresses of legitimate VPN peers.
This reduces the number of external systems capable of reaching the vulnerable VPN functionality.
However, this should be treated as a temporary risk-reduction measure rather than an alternative to installing the security updates.
Check Point notes that this mitigation does not apply to locally managed Spark Firewall deployments.
Stay Safe. Stay Secure.
OP Innovate Research Team



