Check Point has released patches for two newly discovered, high-severity vulnerabilities in its VPN certificate handling mechanisms, each carrying a maximum CVSS score of 9.8. Both flaws could allow unauthenticated remote attackers to execute arbitrary code under certain conditions. The issues affect multiple product lines including the Security Gateways and the Security Management Server. Fixes were made available starting September 9, 2026.
What Went Wrong
The first vulnerability, tracked as CVE-2026-85102, involves improper validation of certificate trust during VPN negotiations on Security Gateways. An attacker exploiting this could trigger remote code execution without prior authentication. The second flaw, CVE-2026-85103, is a heap-based buffer overflow in the ASN.1 certificate decoding process. That bug affects both Quantum Security Gateways and the Quantum Security Management Server.
Both vulnerabilities were self-reported by Check Point and, as of the disclosure, there is no evidence they have been exploited. The versions known to be vulnerable stretch across multiple Quantum branches, including R82.10 (Jumbo Hotfix Take 43 or earlier), R82 (Jumbo Hotfix Take 125 or earlier), and R81.20 (Jumbo Hotfix Take 165 or earlier). Lighter-business line Spark firewall deployments are also listed in an advisory from the Canadian Center for Cyber Security, depending on their VPN setup. Products running these branches need to review the advisories carefully to confirm whether their deployment is affected.
Mitigation and Deployment Challenges
To address the issue, Check Point offers two remediation paths. First, a “Live Patch” mechanism deployed automatically for supported branches—namely R81.20, R82.00, and R82.10—began rolling out on September 9. Second, traditional Jumbo Hotfixes are available for customers to install. However, organizations still on significantly older versions, such as R81.10, have reported no available fixes yet and must rely on mitigation guidance. The advisories suggest disabling certain implied VPN rules, though some users said the instructions are vague or incomplete for their setups.
Additional complicating factors include reports from customers that update rollouts remain delayed in some locations, that download links for advisories sometimes fail in certain browsers, and that it’s unclear for several product lines which builds include the fixes. Check Point has not published indicators of compromise and maintains that no exploit attempts have been detected externally.
Why This Matters
Remote code execution vulnerabilities in VPN systems are particularly alarming because they can bypass authentication layers and allow intrusion from unauthenticated actors—and certificates are at the core of trust in these systems. These kinds of flaws can erode confidence in network security and put sensitive systems at immediate risk. Check Point itself patched similar critical vulnerabilities in the same product lines over the past few months, some of which were already being exploited at the time of disclosure.
What to Watch For: Organizations using Check Point’s Quantum or Spark firewall or management technologies should verify their version and build, apply the Live Patch or Jumbo Hotfix if eligible, and confirm in configuration whether VPN certificates are present—even if VPN functionality is disabled. Vendors need to provide clearer mitigation steps and timely notices when rollouts are delayed or broken in certain environments.
For businesses and IT teams, this is more than just another vulnerability disclosure. It underscores how complex certificate handling—and trust decisions baked into VPNs—remain a high-stakes attack surface. As the threat environment improves detection and exploitation tools, the pressure is on vendors to deliver precise fixes and transparent communication before damage can be done.