Skip to main content
CybersecurityVulnerability Management

Check Point Discloses High-Severity VPN Certificate Flaws Enabling Unauthenticated RCE

Generic technology environment with computer workstations and networking equipment.

On September 9, Check Point disclosed two critical VPN-certificate flaws, CVE-2026-85102 and CVE-2026-85103, each assigned a CVSS score of 9.8 and described as capable of allowing an unauthenticated remote attacker to run code "under specific conditions."

Security Gateways, Security Management Server, and Spark Firewall

Check Point's records list three Quantum branches as affected: R82.10 with Jumbo Hotfix Take 43 or below; R82 with Jumbo Hotfix Take 125 or below; and R81.20 with Jumbo Hotfix Take 165 or below. The vendor's advisories for customers are sk1000117 and sk1000118.

An advisory published the same evening by the Canadian Center for Cyber Security names a broader set of products but does not list versions. That advisory enumerates Security Gateway, Security Management Server, and Spark Firewall. Spark appears twice in the advisory, once for deployments using Site-to-Site or Remote Access VPN and once without that condition.

CVE-2026-85102 and CVE-2026-85103: what the records say

According to Check Point, CVE-2026-85102 is a failure to properly validate certificate trust during VPN negotiation; its CVE record says an unauthenticated remote attacker may be able to run code on the Security Gateway. CVE-2026-85103 is recorded as a heap-based buffer overflow that occurs while the product decodes the ASN.1 structure of a VPN certificate; its record says an unauthenticated remote attacker may be able to run code on both Quantum Security Management and Quantum Security Gateway systems.

Both records carry a CVSS score of 9.8, and Check Point assigned the identifiers and the scores itself. Check Point reported that it found both flaws internally and said it has no indication either has been used in an attack. Check Point has not published indicators of compromise for either flaw.

Check Point Live Patch and Jumbo Hotfix: remediation routes

Check Point offered two routes to remediation. The first is Check Point Live Patch; the company said customers using it are protected automatically as the rollout began on September 9. A Check Point employee in the customer community thread said Live Patch can be installed on top of any Jumbo Hotfix level in R81.20, R82.00 and R82.10 — those three versions were named specifically.

The second route is the traditional Jumbo Hotfix: customers were told to install the latest Jumbo Hotfix for their deployed version once it became available. Check Point began delivering fixes the same day it disclosed the flaws.

Customers on R81.10, mitigation guidance, and rollout gaps

Not all customers reported a clear path to patching. Two customers in the company forum said they run R81.10 and will not move off it for weeks; one said no Jumbo Hotfix and no Live Patch was available for that branch, leaving mitigation as the only option.

The same customer described the advisory's suggested mitigation as "turning off implied rules for VPN," called that guidance too vague to act on, and asked which configuration lines to comment out; another asked how to apply the mitigation without affecting remote users. Those questions received no answer in the thread.

Several accounts also reported the automatic Live Patch rollout had not reached them. Five separate customers said their gateways remained on Take 18 or Take 17 of the urgent security update package on the day of the announcement; one posted an update log showing Take 18 installed on September 1 and nothing since. Several customers reported that download links in the advisories did not work for them; a Check Point staff member replied that links had been checked and were working, while one customer later said advisory links still failed in two browsers though the Live Patch article link worked.

June and July patching context and CISA activity

Check Point's September disclosures come after a busy summer of fixes. In June, the company patched CVE-2026-50751, an authentication bypass in Remote Access VPN and Mobile Access certificate validation; the U.S. Cybersecurity and Infrastructure Security Agency added that CVE to its Known Exploited Vulnerabilities catalog on June 8. In July, Check Point patched CVE-2026-16232, a SmartConsole authentication bypass, and CISA added that flaw to its Known Exploited Vulnerabilities catalog on the day it was disclosed. July's fixes included three flaws, two of which affected the Security Management Server — the same component CVE-2026-85103 reaches.

What this means for security teams, procurement leaders, and customers on older branches

  • Security teams: Verify whether deployed appliances match the affected lists for R82.10, R82, or R81.20 and pursue Check Point Live Patch or the applicable Jumbo Hotfix immediately. Consult advisories sk1000117 and sk1000118 for remediation steps and monitoring guidance because Check Point has not published indicators of compromise for these CVEs.
  • Procurement and operations leaders managing Spark deployments: Note that the Canadian advisory explicitly lists Spark Firewall, including separate mention for deployments using Site-to-Site or Remote Access VPN and for Spark without that condition; the advisories do not, however, list affected Spark versions or which builds contain the fix.
  • Customers on older branches (for example, R81.10): Expect mitigation to be the interim option where Live Patch or Jumbo Hotfix is not available; customer reports indicate the mitigation wording in the advisory may be too vague for immediate application in some environments.

Check Point points customers to advisories sk1000117 and sk1000118 for affected-product lists, mitigation guidance, and remediation steps. Beyond those advisories, the public record reviewed for this article does not state which Spark or Security Management builds contain the fix, which specific conditions the company says the flaws require, or whether installing the fix removes any access an attacker may already have obtained. Those unanswered specifics are the practical details many customers say they need as the patches roll out.

Original story