Check Point has disclosed a critical vulnerability affecting Remote Access VPN and Site-to-Site VPN deployments that could allow an unauthenticated attacker to achieve Remote Code Execution (RCE) on vulnerable Security Gateways. The vulnerability, tracked as CVE-2026-85102, has been assigned a CVSS score of 9.8 (Critical). Check Point states that the issue stems from improper certificate trust validation during VPN negotiation.

At the time of disclosure, Check Point reported no evidence of active exploitation or publicly available proof-of-concept code. However, given the vulnerability's low attack complexity, remote exploitation potential, and exposure of internet-facing VPN services, organisations should prioritize patching and mitigation efforts.

 

Vulnerability Details

According to Check Point, the vulnerability results from improper validation of certificate trust data during VPN negotiation. An attacker can exploit this weakness to advance the VPN negotiation process and potentially execute arbitrary code on a vulnerable gateway without prior authentication.

 

Impact

Critical

Successful exploitation could result in:

  • Full compromise of the affected Security Gateway
  • Unauthorized access to internal networks
  • Deployment of malware or ransomware
  • Credential theft
  • Lateral movement within the environment
  • Service disruption and operational impact

Affected Products

Check Point has identified multiple affected product versions across Security Gateway and related VPN deployments. Vulnerable branches include:

  • R82.20
  • R82.10 Jumbo Hotfix Take 44 or lower
  • R82 Jumbo Hotfix Take 126 or lower
  • R81.20 Jumbo Hotfix Take 166 or lower
  • R81.10 Jumbo Hotfix Take 190 or lower (EoS)
  • R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)

Mitigation and Recommendations

Mitigation

  1. Follow the Check Point Gateway and Management Hardening Administration Guide.
  2. Limit Trusted Clients (GUI clients) to trusted IP addresses/subnets.
    To do so,
    1. In SmartConsole, go to Manage & Settings > Permissions & Administrators > Trusted Clients.
    2. Double-click the client you want to edit.
    3. In the Trusted Client configuration window that opens, change the settings as needed.
      Make sure do not to use "Any" as a Client Type.
    4. Click OK.

Recommendations

Apply Check Point security updates immediately

  • Install the latest Jumbo Hotfix Accumulator appropriate for the deployed version.
  • Verify any Live Patch deployment status. Check Point states customers utilising Live Patch receive protection automatically as rollout occurs.
  • Identify all externally accessible Check Point gateways.
  • Confirm software versions and patch levels.

Review exposed VPN services

If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation.

 

Contact Us