What Changed
Check Point disclosed on September 9, 2026 two critical flaws in VPN certificate handling on Quantum Security Gateway and Security Management products (with Spark deployments called out in secondary advisories). CVE-2026-85102 is improper validation of certificate data during VPN negotiation. CVE-2026-85103 is a heap overflow in VPN certificate ASN.1 decoding. Both carry vendor-assigned CVSS 9.8 scores and can allow unauthenticated remote code execution “under specific conditions” Check Point has not fully detailed publicly. Vendor documents: sk1000117 and sk1000118.
There is no confirmed in-the-wild exploitation as of disclosure. Check Point says it found both issues internally and has not published IoCs because it has seen no evidence of external exploitation. R82.20 is not affected. Remediation on supported branches is LivePatch Take 24 (rollout began September 9) and/or the latest Jumbo Hotfix Accumulator for the deployed release. Public CVE text commonly marks R82.10 Jumbo Take 43 or below, R82 Take 125 or below, and R81.20 Take 165 or below as affected. End-of-support R80 through R81.10 need an upgrade to a fixed supported release.
Why This Matters Operationally
Two remote unauthenticated RCEs in the same certificate path put VPN negotiation—the code that must parse untrusted peer material before a session is fully trusted—on the same management-plane risk pattern as this week’s firewall and ERP kernel stories. Even without confirmed exploitation, Check Point’s 2026 track record on this product family argues for same-week LivePatch or Jumbo, not a wait-and-see. CVE-2026-85103’s reach into Security Management widens blast radius beyond the gateway dataplane.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
What Defenders Should Verify First
- Confirm whether gateways and management are on R82.20 (unaffected) or need LivePatch Take 24 / latest Jumbo for R81.20, R82, or R82.10.
- Validate LivePatch actually landed—do not trust “auto” without inventory evidence.
- For Site-to-Site estates that cannot patch today, tighten UDP/500 and UDP/4500 to known peers and review implied VPN rules—then schedule the Jumbo or LivePatch.
- Treat EoS R80–R81.10 as upgrade-urgent; do not expect LivePatch on abandoned branches.
- With no public IoCs yet, hunt unusual VPN negotiation crashes, unexpected code execution on gateway or management hosts, and certificate-processing anomalies around the disclosure window.
Source Context
- Check Point SKs sk1000117 and sk1000118
- The Hacker News: Check Point twin CVSS 9.8 VPN certificate flaws
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
Free. Weekday mornings. Unsubscribe anytime.
Built from 100+ trusted cybersecurity sources.