Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issuesVolume 342, Issue 2IT Vendor NewsCheck Point

Check Point Patches Critical VPN Vulnerabilities

SecurityWeek, Friday, September 11th, 2026

Check Point patched two critical VPN flaws (CVSS 9.8) that could allow unauthenticated remote code execution.

Check Point released patches for CVE-2026-85102 and CVE-2026-85103, two critical vulnerabilities with CVSS scores of 9.8 that could allow unauthenticated remote code execution.

The first is improper certificate validation during VPN negotiation affecting Security Gateway and Spark Firewall, and the second is a heap overflow in VPN certificate ASN.1 decoding that also affects Security Management Server.

Fixes are available for R82.10, R82, and R81.20, with manual VPN rule definition recommended as mitigation and LivePatch customers patched automatically. Check Point found the flaws internally and reports no evidence of in-the-wild exploitation.

more →  ·  More from Check Point →