Summary
- CVE-2026-85102 and CVE-2026-85103 both carry CVSS scores of 9.8 and can enable unauthenticated remote code execution.
- The vulnerabilities affect Check Point gateways and management infrastructure using remote-access or site-to-site VPN functionality.
- Check Point says it has no indication of active exploitation, while CERT-EU is prioritising exposed perimeter appliances.
Two critical vulnerabilities in Check Point VPN infrastructure can allow unauthenticated attackers to execute code remotely on affected security appliances, placing systems intended to protect network boundaries themselves in the patching queue.
Check Point disclosed CVE-2026-85102 and CVE-2026-85103 on 9 September after identifying the flaws internally. Both carry CVSS scores of 9.8, and the company has issued hotfixes across affected product branches.
Check Point said it has no indication that either vulnerability is being actively exploited. CERT-EU nevertheless issued its own security advisory, recommending that organisations apply the available fixes as soon as possible and give priority to internet-facing and perimeter deployments.
CVE-2026-85102 is an improper validation issue involving certificate data in the VPN negotiation process. An unauthenticated remote attacker can potentially exploit it to execute arbitrary code on a vulnerable Security Gateway where Remote Access VPN or Site-to-Site VPN functionality is configured.
CVE-2026-85103 is a heap-overflow vulnerability in the handling of ASN.1 certificate data. CERT-EU says the flaw can affect both Security Gateway and Security Management Server installations in relevant VPN configurations and can likewise lead to remote code execution.
The affected range spans multiple Check Point generations, including R80-series and R81 releases that have reached end of support, as well as current R81.10.X, R81.20, R82, R82.00.X, and R82.10 installations. Spark Firewall deployments are also included in the advisory.
That breadth creates two different remediation problems. Supported systems can receive the relevant current hotfix, while organisations still operating end-of-support appliances must account for products that may sit at a particularly sensitive network boundary despite having fallen outside normal lifecycle support.
Check Point has also said customers using its Live Patch capability will receive protection through the rollout that began on 9 September. Other environments need the appropriate Jumbo Hotfix or vendor-directed remediation for their deployed release.
The flaws are consequential because VPN gateways are not ordinary application servers. They terminate remote-access or site-to-site connections and commonly sit directly on an organisation’s perimeter. A pre-authentication route to code execution at that layer potentially bypasses the identity controls that would normally govern access through the VPN itself.
Security appliances have repeatedly become high-value targets for that reason. Firewalls, VPN concentrators, remote-access gateways, and management systems combine external reachability with privileged positions inside networks. Their function means they cannot always be shielded behind the controls they themselves provide, while patching can carry operational dependencies that encourage carefully managed maintenance windows.
The current Check Point disclosure is not an active-exploitation incident on the evidence available. Neither the vendor nor CERT-EU has reported observed attacks using the two flaws, and Check Point explicitly says there is no indication of exploitation.
That distinction separates the case from emergency patching driven by a known campaign, but it does not remove the exposure created by publicly reachable systems. Once a critical pre-authentication vulnerability and its fix are public, the interval between disclosure and reliable exploit development becomes part of the operational risk.
CERT-EU’s recommendation to prioritise perimeter and internet-facing appliances reflects that position. Organisations with mixed Check Point estates also face an asset-management question: identifying not only current gateways but older and centrally managed appliances that remain operational, particularly where they provide remote access to internal environments.
For now, the evidence supports urgent remediation rather than an assumption of compromise. Any change in Check Point’s exploitation assessment would materially alter that position, particularly for installations that remain publicly accessible without the relevant hotfix.




