Check Point has disclosed and patched two critical vulnerabilities affecting its VPN certificate processing mechanisms. Both vulnerabilities are rated CVSS 9.8 (Critical) and may enable an unauthenticated remote attacker to achieve Remote Code Execution (RCE) under specific, undisclosed conditions. Check Point has stated that it has not observed active exploitation of either vulnerability at the time of disclosure

Vulnerability Details

CVE-2026-85102

Type: Improper Certificate Trust Validation

This vulnerability stems from a failure to properly validate certificate trust during VPN negotiation. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code on affected Security Gateway devices.

CVE-2026-85103

Type:Heap-Based Buffer Overflow

This vulnerability occurs during the decoding of ASN.1 certificate structures used in VPN certificate processing. Successful exploitation could allow unauthenticated remote code execution against both Quantum Security Gateway and Quantum Security Management Server systems.

Affected Versions

Check Point identifies the following versions as affected:

  • R82.10 with Jumbo Hotfix Take 43 or below
  • R82 with Jumbo Hotfix Take 125 or below
  • R81.20 with Jumbo Hotfix Take 165 or below

These versions are listed as vulnerable and require remediation

Notable Observations

  • The vulnerabilities can be triggered through VPN certificate handling mechanisms.

  • Check Point personnel indicated that CVE-2026-85103 may theoretically be exploitable even when the VPN software blade is disabled if VPN certificates remain present on the system.
  • No Indicators of Compromise (IOCs) have been published.
  • Check Point has reported no evidence of active exploitation as of the disclosure date.
  • The vendor has not publicly disclosed the specific conditions required for exploitation.

Recommended Actions

Immediate

  1. Identify affected Check Point deployments.
  2. Apply the latest available Jumbo Hotfix packages.
  3. Verify Live Patch status if your organization uses Check Point Live Patch services. Check Point states that protected customers began receiving updates from 9 September 2026.
  4. Review internet-exposed Security Gateway and Management Server instances.
  5. Audit VPN certificate configurations and unused certificates.

Short-Term

  • Review administrative access logs for anomalous activity.
  • Validate integrity of gateway and management configurations.
  • Monitor for unexpected certificate-processing events.
  • Ensure backup configurations are available prior to remediation activities.

If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation.

 

Contact Us