Check Point VPN Certificate Vulnerability: Patch Now

Check Point disclosed a Check Point VPN certificate vulnerability pair, CVE-2026-85102 and CVE-2026-85103, both CVSS 9.8, on September 9, and the Dutch National Cyber Security Centre has since warned that large-scale exploitation is likely imminent, even though Check Point itself has not yet observed attacks in the wild. Both flaws allow unauthenticated remote code execution on Security Gateway and Spark Firewall devices before any login occurs.
What Happened
CVE-2026-85102 is a failure to properly validate certificate trust during VPN negotiation on Remote Access and Site-to-Site VPN, letting an unauthenticated remote attacker execute arbitrary code on the Security Gateway. CVE-2026-85103 is a separate heap-based buffer overflow in the VPN certificate ASN.1 decoder, providing a second pre-authentication route to remote code execution on both gateways and Security Management Servers. Affected releases span R81.20, R82, R82.10, R81.10.x and R82.00.x, plus the end-of-support R80 through R80.40, R81, and R81.10 lines; R82.20 is not affected. Check Point published fixes the same day it disclosed the flaws, via LivePatch (Take 24, automatic rollout) and the Jumbo Hotfix Accumulator (Take 44, 126, or 166 depending on version), documented in advisories sk1000117 and sk1000118.
This Check Point VPN certificate vulnerability pair is the third distinct critical Check Point CVE DIESEC has tracked in 2026: CVE-2026-50751, a deprecated-IKEv1 VPN authentication bypass actively exploited by Qilin ransomware (June), and CVE-2026-16232, an unauthenticated SmartConsole token-forgery flaw granting full firewall-management admin access, added to CISA’s Known Exploited Vulnerabilities catalog (July).
Why It Matters
Check Point Security Gateways and Spark Firewalls are widely deployed across DACH banking, insurance, and manufacturing environments, often specifically for their compliance-friendly management model. Three critical, independently disclosed vulnerabilities from the same vendor within twelve months is a pattern a vendor-risk review should treat as a signal, not three isolated tickets to close and forget. The Dutch NCSC’s “imminent exploitation” language, issued before Check Point itself confirmed any attack activity, is also a reminder that a vendor’s own exploitation-status line reflects what that vendor has observed, not a guarantee about what is happening elsewhere.
What You Should Do Now
- Apply LivePatch Take 24 or the appropriate Jumbo Hotfix Accumulator take (44, 126, or 166, depending on your version) today; check sk1000117 and sk1000118 for the exact take for your release.
- Confirm whether any of your gateways are still running end-of-support releases (R80–R80.40, R81, R81.10); these remain affected and will not receive further security updates beyond this fix.
- If immediate patching is not possible, review whether Remote Access and Site-to-Site VPN termination can be temporarily restricted or monitored more closely until the hotfix is applied.
- Monitor Check Point’s own advisories and the Dutch NCSC bulletin for updates; both flaws are pre-authentication and the exploitation-likelihood assessment may change quickly.
DIESEC Perspective
Three critical Check Point vulnerabilities in under a year (a VPN authentication bypass exploited by ransomware, a management-console token-forgery flaw, and now a VPN certificate-handling RCE pair) is no longer a one-off. We increasingly recommend that Mittelstand security teams track vendor-specific CVE frequency as its own risk metric in vendor reviews, not just individual CVSS scores in isolation.
Not sure whether your Check Point estate is fully patched against all three 2026 disclosures, not just the newest one? Contact DIESEC for a rapid patch verification and firewall configuration review.
Sources: The Hacker News | BleepingComputer
Published: 2026-09-16 | Category: Vulnerabilities & Patches | ~4 min read

