Check Point patched two critical, unauthenticated remote code execution flaws in how its firewall and management products handle VPN certificates, disclosing both to customers on September 9 and beginning fixes the same day. CVE-2026-85102 is a failure to properly validate certificate trust during VPN negotiation, letting an unauthenticated attacker potentially run code on a Security Gateway. CVE-2026-85103 is a heap-based buffer overflow triggered while the product decodes the ASN.1 structure of a VPN certificate, reaching Quantum Security Management and Quantum Security Gateway systems. Check Point assigned both a CVSS score of 9.8 and said it found the flaws itself, with no evidence yet of active exploitation. The Canadian Centre for Cyber Security issued its own advisory the same evening, listing Security Gateway, Security Management Server and the Spark small-business firewall line as affected.

Check Point is offering two fix paths: an automatic Live Patch rollout that began September 9 for supported Jumbo Hotfix levels on R81.20, R82.00 and R82.10, or a standard Jumbo Hotfix install. Customers still running older branches such as R81.10 reported in Check Point’s own community forum that no Live Patch or Jumbo Hotfix was yet available for their version, leaving configuration-level mitigation as the only near-term option.

The original insight sits in a detail Check Point staff confirmed in that same customer thread: CVE-2026-85103 lives in certificate processing generally, not the VPN negotiation path specifically, so a gateway with the VPN software blade turned off entirely can still be exposed if it has VPN certificates present. Security teams that scoped their exposure assessment to “do we terminate VPN connections on this box” rather than “does this box process VPN certificates at all” are working from the wrong question, and should re-check every Check Point gateway in their estate against the patch, not just the ones actively serving VPN traffic.

Source: Canadian Centre for Cyber Security

Related: A Senator Wants the NSA to Rethink VPN Advice and SonicWall Patches Its Second SMA Zero-Day Pair.