Check Point has disclosed a critical vulnerability affecting Remote Access VPN and Site-to-Site VPN deployments that could allow an unauthenticated attacker to achieve Remote Code Execution (RCE) on vulnerable Security Gateways. The vulnerability, tracked as CVE-2026-85102, has been assigned a CVSS score of 9.8 (Critical). Check Point states that the issue stems from improper certificate trust validation during VPN negotiation.
At the time of disclosure, Check Point reported no evidence of active exploitation or publicly available proof-of-concept code. However, given the vulnerability's low attack complexity, remote exploitation potential, and exposure of internet-facing VPN services, organisations should prioritize patching and mitigation efforts.
According to Check Point, the vulnerability results from improper validation of certificate trust data during VPN negotiation. An attacker can exploit this weakness to advance the VPN negotiation process and potentially execute arbitrary code on a vulnerable gateway without prior authentication.
Critical
Successful exploitation could result in:
Affected Products
Check Point has identified multiple affected product versions across Security Gateway and related VPN deployments. Vulnerable branches include:
Mitigation
Apply Check Point security updates immediately
If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation.